Impact
Open ISES Tickets versions prior to 3.44.2 contain a reflected cross‑site scripting flaw in single_unit.php. The flaw allows an authenticated attacker to inject arbitrary JavaScript by passing an unsanitized value through the id GET parameter directly into an HTML attribute. When a victim visits a crafted URL, the script executes in the victim’s browser, potentially stealing session cookies or performing other malicious actions.
Affected Systems
The vulnerability affects the Open ISES Tickets application from the vendor openises. Versions earlier than 3.44.2 are susceptible. No other products are listed as affected.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting limited known exploitation. Because the flaw requires an authenticated victim to visit a malicious link, the attack vector is a web‑based reflected XSS, which can be triggered via phishing or social engineering. Although the risk is moderate, the potential impact on confidentiality and integrity warrants prompt attention.
OpenCVE Enrichment