Reflected Cross-Site Scripting Vulnerability in Open ISES Tickets by Open ISES
CVE-2026-48227
5.1MEDIUM
What is CVE-2026-48227?
Open ISES Tickets versions prior to 3.44.2 contain a reflected cross-site scripting vulnerability in the patient.php file. This flaw permits authenticated attackers to inject arbitrary JavaScript code by manipulating the unsanitized id and ticket_id GET parameters directly into the HTML form action URL. When exploited, this vulnerability enables malicious requests to execute JavaScript payloads in a victim's browser, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
Tickets 0 < 3.44.2
