PT-2026-42524 · Unknown · Open Ises Tickets
Published
2026-05-21
·
Updated
2026-05-21
·
CVE-2026-48246
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open ISES Tickets versions prior to 3.44.2
Description
The software disables TLS certificate verification when issuing outbound HTTPS requests for Google Maps Directions API lookups during incident report generation. This occurs in the 'ajax/reports.php' endpoint by setting the
CURLOPT SSL VERIFYPEER variable to false and failing to set CURLOPT SSL VERIFYHOST. An attacker positioned on the network path between the server and the remote endpoint can present a forged certificate to intercept, monitor, or modify the request and response, including API keys or session-bearing data in transit.Recommendations
Update to version 3.44.2 or later.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Ises Tickets