Reflected Cross-Site Scripting Vulnerability in Open ISES Tickets by Open ISES
CVE-2026-35008
5.1MEDIUM
What is CVE-2026-35008?
Open ISES Tickets prior to version 3.44.2 contains a reflected cross-site scripting vulnerability in the single.php file. This flaw allows authenticated attackers to exploit the unsanitized ticket_id GET parameter, injecting arbitrary JavaScript into an HTML attribute. Through crafted URLs containing malicious payloads, attackers can execute harmful scripts in the browsers of unsuspecting users who access such links.
Affected Version(s)
tickets 0
