Reflected Cross-Site Scripting in Open ISES Tickets by Open ISES
CVE-2026-35009

5.1MEDIUM

Key Information:

Vendor

Openises

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-35009?

The Open ISES Tickets application before version 3.44.2 is susceptible to a reflected cross-site scripting vulnerability. This flaw allows authenticated attackers to inject arbitrary JavaScript into the application through the ticket_id GET parameter. By manipulating the parameter to include an unsanitized value, attackers can craft malicious URLs that, when accessed by victims, execute the injected script in their browsers. This vulnerability poses a significant risk, enabling potential exploitation that could compromise user data and security.

Affected Version(s)

tickets 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

philopentest
VulnCheck
.