← back
CVE-2026-48244

Open ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in settings.inc.php

CVSS 6.9 MEDIUMEPSS 0.2%CWE-798
Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Google Cloud project.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Open ISES · Tickets

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →