Executive brief
Open ISES Tickets, a support ticketing system, contained a hardcoded Google Maps API key within its public source code. An unauthorized individual could extract this key and use it to make map-related requests that are billed to the original owner's Google Cloud account. This could lead to unexpected financial charges and the exhaustion of the organization's Google Maps service quota.
Technical details
A hardcoded Google Maps API key was discovered in the 'settings.inc.php' file of Open ISES Tickets versions prior to 3.44.2. Because this file was committed to a public GitHub repository, the credential is accessible to any user with read access to the source code. An attacker can extract this key and utilize it to authenticate requests to the Google Maps Platform. These unauthorized requests are billed against the project owner's Google Cloud account, potentially leading to financial loss or service denial if usage limits are reached. The issue was addressed in version 3.44.2 by removing the hardcoded secret.
Affected products
- Open ISES Tickets before 3.44.2
Timeline
- 2026-04-01: patched: Fix committed to repository.
- 2026-04-02: advisory: Version 3.44.2 released.
- 2026-05-21: disclosed: CVE published.