Junglewise Threat Intelligence

CVE-2026-48229: Open ISES Tickets reflected XSS in routes_i.php

CVE-2026-48229 · Severity: medium · CVSS 5.4 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets is an open-source ticketing system used for managing support requests and incident tracking. A security flaw in the software allows an attacker to trick a user into executing malicious code within their web browser. If successful, this could allow the attacker to perform actions on behalf of the user, potentially leading to unauthorized access to support tickets or sensitive system information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The flaw is located in 'routes_i.php' (and several other files including 'routes_nm.php') where the 'ticket_id' GET/POST parameter is rendered into HTML hidden input value attributes without proper sanitization or encoding. An authenticated attacker can exploit this by crafting a malicious URL or form submission containing a JavaScript payload. When a victim visits the link, the payload executes in the context of their session, potentially allowing for session hijacking or unauthorized data modification. The vendor has addressed this in version 3.44.2 by implementing 'intval()' and 'htmlspecialchars()' for input validation.

Affected products

  • Open ISES Tickets < 3.44.2

Timeline

  • 2026-04-01: patched: Fixes committed to GitHub repository.
  • 2026-04-02: advisory: Version 3.44.2 released.
  • 2026-05-21: disclosed: CVE-2026-48229 published.

References

Related threats