Impact
Open ISES Tickets versions before 3.44.2 contain an unsanitized ticket_id parameter that is reflected into a hidden input field, enabling an attacker to inject and execute arbitrary JavaScript in the victim’s browser when a crafted URL is visited.
Affected Systems
The affected system is the openises:tickets product, all releases prior to version 3.44.2.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate risk; the vulnerability requires authenticated access and a user to click a malicious link, yet it can lead to phishing, session hijacking or data theft. With no EPSS data and absence from the KEV catalog, exploitation remains uncertain, but the lack of input sanitization suggests it could be abused if an attacker obtains user credentials or tricks users into visiting the URL.
OpenCVE Enrichment