Executive brief
Open ISES Tickets is an incident management system used for tracking and managing service requests. A security flaw in the software allows logged-in users to execute unauthorized database commands. This could lead to the theft of sensitive information, unauthorized modification of records, or the deletion of critical incident data.
Technical details
A SQL injection vulnerability exists in Open ISES Tickets versions prior to 3.44.2 within the 'ajax/fullsit_incidents.php' component. The root cause is the improper neutralization of the 'offset' GET parameter, which is directly concatenated into the LIMIT clause of a SQL SELECT statement. An authenticated attacker with network access can exploit this by sending specially crafted requests to manipulate query logic. Successful exploitation allows the attacker to read, modify, or delete data within the underlying database. The issue is resolved in version 3.44.2 by implementing proper input sanitization (e.g., using intval()).
Affected products
- Open ISES Tickets before 3.44.2
Timeline
- 2026-04-01: patched: Fix committed to repository
- 2026-04-02: advisory: Release v3.44.2 published
- 2026-05-21: disclosed: CVE published to NVD