CVE-2026-48217: medium-severity vulnerability in Open ISES Tickets
Open ISES Tickets < 3.44.2 Reflected XSS via delete_module.php Multiple POST Parameters
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.3%
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
nono source reports it
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_module.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the multiple POST parameters (module_choice, flag, confirmation) directly into rendered HTML content and form action attributes. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
Open ISES · TicketsRelated CVEs — Open ISES Tickets
In the same product, most dangerous first.
CVE-2026-48241CRITICALOpen ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in loader.phpEPSS 0.5%CVE-2026-48242CRITICALOpen ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in import_mdb.phpEPSS 0.5%CVE-2026-48235HIGHOpen ISES Tickets < 3.44.2 SQL Injection in incs/remotes.inc.php via External GPS Tracker DataEPSS 0.4%CVE-2026-48245MEDIUMOpen ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in tables.phpEPSS 0.4%CVE-2026-48244MEDIUMOpen ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in settings.inc.phpEPSS 0.4%CVE-2026-48243MEDIUMOpen ISES Tickets < 3.44.2 Hardcoded WhitePages API Key in wp1.phpEPSS 0.4%