Junglewise Threat Intelligence

CVE-2026-48227: Open ISES Tickets reflected XSS in patient.php

CVE-2026-48227 · Severity: medium · CVSS 5.4 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets, an open-source incident and emergency services ticketing system, contains a security flaw in its patient management component. An authenticated attacker can trick another user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the victim's browser. This could lead to the theft of session cookies, unauthorized access to patient data, or the performance of actions on behalf of the victim.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2 within the patient.php file. The application fails to sanitize the 'id' and 'ticket_id' GET parameters before embedding them into an HTML form's action URL. An authenticated attacker can exploit this by crafting a URL containing a malicious JavaScript payload and enticing a victim to visit it. When the victim's browser renders the page, the payload executes in the context of the victim's session. This can result in session hijacking or unauthorized data manipulation. The issue was addressed in version 3.44.2 by implementing proper input validation using intval() and output encoding.

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to repository
  • 2026-04-02: advisory: Version 3.44.2 released
  • 2026-05-21: disclosed: CVE published and NVD entry created

References

Related threats