Executive brief
Open ISES Tickets is an open-source incident management and ticketing system. A security flaw in the software allows an attacker to inject malicious scripts into the application. If a user interacts with a specially crafted link or form, the attacker could execute code in the user's browser, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The flaw is located in the ics214.php component, where the 'frm_add_str' POST parameter is processed without sufficient sanitization before being rendered into an HTML hidden input's value attribute. An authenticated attacker can exploit this by crafting a malicious request that, when processed by a victim's browser, executes arbitrary JavaScript in the context of the victim's session. This can lead to session hijacking or unauthorized data modification. The issue was addressed in version 3.44.2 by implementing proper output encoding using htmlspecialchars().
Affected products
- Open ISES Tickets < 3.44.2
Timeline
- 2026-04-01: patched: Fix committed to repository
- 2026-04-02: advisory: Version 3.44.2 released
- 2026-05-21: disclosed: CVE published to NVD