PT-2026-42516 · Openises+1 · Tickets
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Open ISES Tickets versions prior to 3.44.2
Description
An issue exists where the 'ajax/mobile main.php' endpoint fails to sanitize the
id GET parameter before concatenating it into the WHERE clause of a SELECT statement used for a ticket-existence sanity check. This allows authenticated attackers to manipulate query semantics to read, modify, or destroy database contents via SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution.Recommendations
Update to version 3.44.2 or later.
Avoid using the
id parameter in the 'ajax/mobile main.php' endpoint until the update is applied.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tickets