Executive brief
Open ISES Tickets is an open-source ticketing and incident management system. A security flaw in the database loading component allows logged-in users to manipulate database queries. This could lead to unauthorized access to sensitive information, data modification, or the deletion of records within the system's database.
Technical details
A SQL injection vulnerability exists in Open ISES Tickets versions prior to 3.44.2 within the 'db_loader.php' component. The root cause is the lack of sanitization for multiple POST parameters (including 'ticketsdb', 'ticketshost', 'ticketsuser', and 'ticketspassword') which are concatenated directly into mysqli connection arguments and dynamic SQL queries. An authenticated attacker with network access can provide malicious input to these parameters to alter query semantics. This allows for the unauthorized reading, modification, or destruction of database contents. The issue is resolved in version 3.44.2.
Affected products
- Open ISES Tickets before 3.44.2
Timeline
- 2026-04-01: patched: Fix committed to GitHub repository
- 2026-04-02: advisory: Version 3.44.2 released with security fixes
- 2026-05-21: disclosed: CVE published to NVD