PT-2026-42518 · Openises+1 · Tickets

·

CVE-2026-48240

·

Published

2026-05-21

·

Updated

2026-07-23

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Open ISES Tickets versions prior to 3.44.2
Description An issue exists in the 'ajax/statistics.php' endpoint where the tick id and f tick id POST parameters are concatenated into WHERE clauses of SELECT statements in statistics rollup queries without proper sanitization. This allows authenticated attackers to manipulate query semantics to read, modify, or destroy database contents via SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution.
Recommendations Update to version 3.44.2 or later. Avoid using the tick id and f tick id parameters in the 'ajax/statistics.php' endpoint until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48240

Affected Products

Tickets