Reflected Cross-Site Scripting Vulnerability in Open ISES Tickets by Open ISES
CVE-2026-35016
5.1MEDIUM
What is CVE-2026-35016?
Open ISES Tickets prior to version 3.44.2 contains a reflected cross-site scripting vulnerability in the search.php file. This flaw allows authenticated attackers to inject arbitrary JavaScript by submitting unsanitized input through the frm_query POST parameter. The malicious JavaScript is then executed in the victim’s browser as soon as the form is submitted, potentially leading to unauthorized access or data theft. Users of Open ISES Tickets are advised to update to the latest version to mitigate this risk.
Affected Version(s)
tickets 0
