Reflected Cross-Site Scripting Vulnerability in Open ISES Tickets by Open ISES
CVE-2026-35015

5.1MEDIUM

Key Information:

Vendor

Openises

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-35015?

The Open ISES Tickets application prior to version 3.44.2 is vulnerable to a reflected cross-site scripting (XSS) attack due to insufficient sanitization of user input in the 'the_ticket' GET parameter. This allows authenticated users to craft malicious URLs that can be used to deliver arbitrary JavaScript payloads executed in the context of another user's browser. If a victim unknowingly clicks on the crafted link, it could lead to session hijacking, data leakage, or other malicious actions facilitated by executing unauthorized scripts in the user's session.

Affected Version(s)

tickets 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

philopentest
VulnCheck
.