Reflected Cross-Site Scripting Vulnerability in Open ISES Tickets by Open ISES
CVE-2026-48221
5.1MEDIUM
What is CVE-2026-48221?
An identified reflected cross-site scripting vulnerability allows authenticated attackers of Open ISES Tickets to inject arbitrary JavaScript. This occurs through the frm_add_str POST parameter, where an unsanitized value is inserted into an HTML form's hidden input attribute. Attackers can exploit this flaw by crafting a malicious request that executes a JavaScript payload in the victim's browser when the server's response is rendered.
Affected Version(s)
Tickets 0 < 3.44.2
