Reflected Cross-Site Scripting Vulnerability in Open ISES Tickets by Open ISES
CVE-2026-35016

5.1MEDIUM

Key Information:

Vendor

Openises

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-35016?

Open ISES Tickets prior to version 3.44.2 contains a reflected cross-site scripting vulnerability in the search.php file. This flaw allows authenticated attackers to inject arbitrary JavaScript by submitting unsanitized input through the frm_query POST parameter. The malicious JavaScript is then executed in the victim’s browser as soon as the form is submitted, potentially leading to unauthorized access or data theft. Users of Open ISES Tickets are advised to update to the latest version to mitigate this risk.

Affected Version(s)

tickets 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

philopentest
VulnCheck
.