PT-2026-42520 · Openises · Tickets

Published

2026-05-21

·

Updated

2026-05-21

·

CVE-2026-48242

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the source to obtain valid configuration values that may match deployed installations.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2026-48242

Affected Products

Tickets