PT-2026-42525 · Unknown · Open Ises Tickets
CVE-2026-48247
·
Published
2026-05-21
·
Updated
2026-05-21
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Open ISES Tickets versions prior to 3.44.2
Description
TLS certificate verification is disabled in the file incs/functions.inc.php by setting the
CURLOPT SSL VERIFYPEER variable to false and failing to set CURLOPT SSL VERIFYHOST during general-purpose outbound HTTPS requests issued by shared helper functions. This allows an attacker positioned on the network path between the server and the remote endpoint to present a forged certificate to intercept, monitor, or modify requests and responses, including session-bearing data or API keys in transit.Recommendations
Update to version 3.44.2.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Ises Tickets