Reflected Cross-Site Scripting Vulnerability in Open ISES Tickets by Open ISES
CVE-2026-35015
5.1MEDIUM
What is CVE-2026-35015?
The Open ISES Tickets application prior to version 3.44.2 is vulnerable to a reflected cross-site scripting (XSS) attack due to insufficient sanitization of user input in the 'the_ticket' GET parameter. This allows authenticated users to craft malicious URLs that can be used to deliver arbitrary JavaScript payloads executed in the context of another user's browser. If a victim unknowingly clicks on the crafted link, it could lead to session hijacking, data leakage, or other malicious actions facilitated by executing unauthorized scripts in the user's session.
Affected Version(s)
tickets 0
