PT-2026-42509 · Unknown · Open Ises Tickets

Published

2026-05-21

·

Updated

2026-05-22

·

CVE-2026-48231

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Open ISES Tickets versions prior to 3.44.2
Description An issue exists in the 'tables.php' endpoint where multiple POST parameters, specifically tablename, indexname, and sortby, are concatenated into table or column identifiers within dynamically constructed SELECT, UPDATE, and DELETE statements without proper sanitization. This allows authenticated attackers to manipulate query semantics to read, modify, or delete database contents. SQL injection is a technique where an attacker inserts malicious SQL code into a query, allowing them to interfere with the queries that an application makes to its database.
Recommendations Update to version 3.44.2 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48231

Affected Products

Open Ises Tickets