PT-2026-42517 · Openises+1 · Tickets
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Open ISES Tickets versions prior to 3.44.2
Description
An issue exists in the incidents summary report where the
tick id POST parameter is concatenated into the WHERE clause of SELECT statements without sanitization. This allows authenticated attackers to craft requests that alter query semantics to read, modify, or destroy database contents via the 'ajax/reports.php' endpoint. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.Recommendations
Update to version 3.44.2 or later.
Avoid using the
tick id parameter in the 'ajax/reports.php' endpoint until the update is applied.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tickets