Executive brief
Open ISES Tickets is an incident management and ticketing system. In versions prior to 3.44.2, the software fails to verify security certificates when communicating with Google Maps services. This allows a sophisticated attacker positioned on the network to intercept or modify sensitive data, such as API keys or incident report details, potentially compromising the privacy and integrity of the organization's data.
Technical details
The vulnerability exists in ajax/reports.php due to the improper configuration of cURL options. Specifically, the application sets CURLOPT_SSL_VERIFYPEER to false and fails to set CURLOPT_SSL_VERIFYHOST when performing Google Maps Directions API lookups during incident report generation. This lack of certificate validation allows an attacker with Man-in-the-Middle (MitM) capabilities to present a forged certificate. Successful exploitation enables the interception, monitoring, or modification of outbound requests and responses, potentially exposing sensitive API keys or session data. The issue is resolved in version 3.44.2.
Affected products
- Open ISES Tickets before 3.44.2
Timeline
- 2026-04-01: patched: Fix committed to GitHub repository
- 2026-04-02: advisory: Release v3.44.2 published
- 2026-05-21: disclosed: CVE-2026-48246 published