Executive brief
Open ISES Tickets, an open-source ticketing and incident management system, is vulnerable to a security flaw in its data import component. An attacker can trick a logged-in user into executing malicious scripts within their web browser. This could lead to unauthorized actions being performed on behalf of the user, potential theft of session information, or the defacement of the application interface.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the `ticketsmdb_import.php` component of Open ISES Tickets. The application fails to sanitize multiple POST parameters—including mdbhost, mdbdb, mdbuser, mdbpassword, mdbprefix, ticketshost, ticketsdb, ticketsuser, ticketspassword, and ticketsprefix—before rendering them into the value attributes of hidden HTML input fields. An authenticated attacker can exploit this by crafting a malicious request that, when processed by a victim's browser, executes arbitrary JavaScript in the context of the victim's session. This vulnerability was addressed in version 3.44.2 by implementing proper output encoding using htmlspecialchars().
Affected products
- Open ISES Tickets before 3.44.2
Timeline
- 2026-04-01: patched: Fix committed to repository
- 2026-04-02: advisory: Version 3.44.2 released
- 2026-05-21: disclosed: CVE published to NVD