MEDIUM
Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter
Published May 20, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.29%
Description
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attackers can craft a malicious URL containing a JavaScript payload in the ticket_id parameter that executes in the victim's browser when the URL is visited.
Affected products
-
- Version 0StatusaffectedConstraints<3.44.2
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31184 Advisory
- https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a9f2dbff patch
- https://github.com/openises/tickets/releases/tag/v3.44.2 release-notes
- https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-routes-nm-php-ticket-id-parameter third-party-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published May 20, 2026
Updated Jul 28, 2026
Reserved Mar 31, 2026
Link CVE-2026-35014
CISA Vulnrichment
Updated May 21, 2026
ENISA EUVD
EUVD-2026-31184 Assigner VulnCheck
Published May 20, 2026
Updated Jul 28, 2026
Exploited since n/a
Link EUVD-2026-31184