Reflected Cross-Site Scripting Vulnerability in Open ISES Tickets by Open ISES
CVE-2026-35008

5.1MEDIUM

Key Information:

Vendor

Openises

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-35008?

Open ISES Tickets prior to version 3.44.2 contains a reflected cross-site scripting vulnerability in the single.php file. This flaw allows authenticated attackers to exploit the unsanitized ticket_id GET parameter, injecting arbitrary JavaScript into an HTML attribute. Through crafted URLs containing malicious payloads, attackers can execute harmful scripts in the browsers of unsuspecting users who access such links.

Affected Version(s)

tickets 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

philopentest
VulnCheck
.