Executive brief
Open ISES Tickets is an open-source incident tracking system. A security flaw in the software allows logged-in users to execute unauthorized database commands. This could lead to the theft of sensitive incident data, unauthorized modification of records, or the deletion of database contents, potentially disrupting emergency response operations.
Technical details
A SQL injection vulnerability exists in Open ISES Tickets versions prior to 3.44.2 within the 'ajax/sit_incidents.php' component. The application fails to sanitize the 'offset' GET parameter before concatenating it into the LIMIT clause of a SQL SELECT statement. An authenticated attacker with network access can exploit this by sending specially crafted requests to manipulate the query logic. Successful exploitation allows for unauthorized reading, modification, or destruction of database records. The issue is addressed in version 3.44.2 by implementing proper input validation (such as intval()).
Affected products
- Open ISES Tickets < 3.44.2
Timeline
- 2026-04-01: patched: Fix committed to repository
- 2026-04-02: advisory: Release v3.44.2 published
- 2026-05-21: disclosed: CVE published to NVD