Junglewise Threat Intelligence

CVE-2026-48228: Open ISES Tickets reflected XSS in patient_w.php

CVE-2026-48228 · Severity: medium · CVSS 5.4 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets is an open-source incident and patient tracking system. A security flaw in the software allows an attacker to send a specially crafted link to a logged-in user that, if clicked, executes malicious code in their browser. This could allow an attacker to steal session information, perform actions on behalf of the user, or compromise sensitive patient data.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets before version 3.44.2 within the 'patient_w.php' component. The application fails to sanitize the 'id' and 'ticket_id' GET parameters before embedding them directly into an HTML form's action URL. An authenticated attacker can exploit this by tricking a victim into clicking a malicious URL containing a JavaScript payload. When the victim's browser renders the response, the payload executes within the context of the victim's session. This vulnerability was addressed in version 3.44.2 by implementing proper input validation using 'intval()' and 'htmlspecialchars()'.

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to GitHub repository
  • 2026-04-02: advisory: Release v3.44.2 published
  • 2026-05-21: disclosed: CVE published and NVD record created

References

Related threats