PT-2026-42509 · Unknown · Open Ises Tickets
Published
2026-05-21
·
Updated
2026-05-22
·
CVE-2026-48231
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Open ISES Tickets versions prior to 3.44.2
Description
An issue exists in the 'tables.php' endpoint where multiple POST parameters, specifically
tablename, indexname, and sortby, are concatenated into table or column identifiers within dynamically constructed SELECT, UPDATE, and DELETE statements without proper sanitization. This allows authenticated attackers to manipulate query semantics to read, modify, or delete database contents. SQL injection is a technique where an attacker inserts malicious SQL code into a query, allowing them to interfere with the queries that an application makes to its database.Recommendations
Update to version 3.44.2 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Ises Tickets