CVE-2026-48244: fallo de gravedad media en Open ISES Tickets
Open ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in settings.inc.php
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.9epss 0.4%
probabilidad de explotación
0.4%top 70% de las CVE
explotación observada
noninguna fuente lo reporta
Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Google Cloud project.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
Open ISES · TicketsCVEs relacionadas — Open ISES Tickets
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-48241CRITICALOpen ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in loader.phpEPSS 0.5%CVE-2026-48242CRITICALOpen ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in import_mdb.phpEPSS 0.5%CVE-2026-48235HIGHOpen ISES Tickets < 3.44.2 SQL Injection in incs/remotes.inc.php via External GPS Tracker DataEPSS 0.4%CVE-2026-48245MEDIUMOpen ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in tables.phpEPSS 0.4%CVE-2026-48243MEDIUMOpen ISES Tickets < 3.44.2 Hardcoded WhitePages API Key in wp1.phpEPSS 0.4%CVE-2026-48240HIGHOpen ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id ParametersEPSS 0.4%