Impact
The vulnerability resides in Open ISES Tickets code before version 3.44.2, where a WhitePages reverse‑phone API key is hard‑coded into wp1.php and committed to the public repository. This is an instance of a CWE‑798 Hardcoded Credentials weakness. Anyone with read access to the source tree can copy the key and use it to issue calls to the WhitePages service. If abused, the key enables unauthorized API usage that will be billed to or rate‑limited against the original owner’s account, potentially incurring financial costs and compromising service availability.
Affected Systems
Open ISES:Tickets software prior to release 3.44.2 contains the hard‑coded key. Users of any earlier build are potentially exposed.
Risk and Exploitability
The CVSS score of 6.9 classifies this as a moderate‑risk vulnerability, and the EPSS is not available. It is not listed in the CISA KEV catalog. Attackers can exploit it by simply accessing the public code; the vulnerability does not require privileged conditions beyond read access to the repository.
OpenCVE Enrichment