Junglewise Threat Intelligence

CVE-2026-48240: Open ISES Tickets SQL injection in ajax/statistics.php

CVE-2026-48240 · Severity: high · CVSS 7.1 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets, an open-source ticketing and incident management system, contains a security flaw in its statistics reporting component. An authorized user can exploit this vulnerability to bypass security controls and directly interact with the underlying database. This could allow an attacker to view sensitive information, modify records, or delete critical data, potentially disrupting operations and compromising user privacy.

Technical details

A SQL injection vulnerability exists in Open ISES Tickets versions prior to 3.44.2 within the `ajax/statistics.php` file. The root cause is the lack of sanitization for the `tick_id` and `f_tick_id` POST parameters, which are directly concatenated into the WHERE clauses of SELECT statements used for statistics rollup queries. An authenticated attacker with network access can provide malicious input to these parameters to alter the intended SQL query logic. Successful exploitation allows for unauthorized reading, modification, or deletion of database contents. The issue is resolved in version 3.44.2 by implementing proper input validation (such as `intval()`).

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Initial security fixes committed to repository.
  • 2026-04-02: advisory: Version 3.44.2 released as a critical security update.
  • 2026-05-21: disclosed: CVE-2026-48240 published.

References

Related threats