Junglewise Threat Intelligence

CVE-2026-48234: Open ISES Tickets SQL injection in portal/ajax/list_requests.php

CVE-2026-48234 · Severity: high · CVSS 7.1 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets is an open-source ticket management system. A security flaw in the portal's request listing feature allows logged-in users to execute unauthorized database commands. This could lead to the theft of sensitive information, unauthorized modification of records, or the deletion of system data.

Technical details

A SQL injection vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The root cause is the lack of sanitization for the 'sort' and 'dir' GET parameters within the portal/ajax/list_requests.php file, which are directly concatenated into the ORDER BY clause of a SELECT statement. An authenticated attacker with network access can exploit this by crafting malicious requests to alter query logic. Successful exploitation allows the attacker to read, modify, or delete data within the underlying database. The issue is resolved in version 3.44.2.

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Initial security fixes committed to repository
  • 2026-04-02: advisory: Release v3.44.2 published as a critical security update
  • 2026-05-21: disclosed: CVE-2026-48234 published to NVD

References

Related threats