Open ISES Tickets
- < 3.44.2
A reflected cross-site scripting vulnerability has been identified in Open ISES Tickets versions prior to 3.44.2. The issue resides in circle.php, where authenticated attackers can inject arbitrary JavaScript. This is achieved by sending an unsanitized value through the frm_id POST parameter, which is then directly inserted into an HTML form input value attribute. The injected script executes in the context of the victim's browser when the response is displayed.
Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the context of the user's browser.
To reproduce this vulnerability, an authenticated user can send a POST request to circle.php with a crafted frm_id parameter that includes a JavaScript payload. The payload will be executed in the browser when the response is rendered.
Users are advised to upgrade to Open ISES Tickets version 3.44.2 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.