Junglewise Threat Intelligence

CVE-2026-48225: Open ISES Tickets reflected XSS in landb.php

CVE-2026-48225 · Severity: medium · CVSS 5.4 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets is an open-source ticketing and incident management system. A security flaw in the software allows an attacker to inject malicious scripts into the application. If a user interacts with a specially crafted link or form, the attacker could steal login credentials, hijack user sessions, or perform unauthorized actions on behalf of the victim.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The flaw is located in landb.php, where the '_type' POST parameter is processed without sufficient sanitization before being rendered into the 'value' attribute of a hidden HTML input field. An authenticated attacker can exploit this by crafting a malicious request containing a JavaScript payload. When a victim's browser renders the response, the payload executes in the context of the victim's session. This can lead to session hijacking or unauthorized data access. The issue was addressed in version 3.44.2 by implementing proper output encoding using htmlspecialchars().

Affected products

  • Open ISES Tickets < 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to GitHub repository.
  • 2026-04-02: advisory: Version 3.44.2 released.
  • 2026-05-21: disclosed: CVE-2026-48225 published.

References

Related threats