Junglewise Threat Intelligence

CVE-2026-48235: Open ISES Tickets SQL injection in incs/remotes.inc.php

CVE-2026-48235 · Severity: high · CVSS 8.2 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets is an incident management system used for tracking emergency responders and assignments. A security flaw in how the system processes GPS data from external services like Google Latitude allows an attacker to manipulate database records. By sending specially crafted location data, an attacker could change responder locations, alter tracking history, or interfere with task assignments, potentially disrupting emergency operations.

Technical details

A SQL injection vulnerability exists in Open ISES Tickets versions prior to 3.44.2 within the 'incs/remotes.inc.php' component. The application fails to sanitize multiple parameters—including latitude, longitude, callsign, mph, altitude, and timestamp—parsed from external GPS tracking service XML/JSON responses (such as InstaMapper and Google Latitude). These values are concatenated directly into SQL UPDATE and INSERT statements. An attacker who can compromise or impersonate the remote GPS tracker endpoint can execute arbitrary SQL commands to manipulate responder location data, tracks, and assignment tables. The issue is resolved in version 3.44.2 by implementing proper input validation (e.g., floatval() and intval()) and sanitization.

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Initial security fixes committed to repository
  • 2026-04-02: advisory: Release v3.44.2 published with security notes
  • 2026-05-21: disclosed: CVE-2026-48235 published to NVD

References

Related threats