Medium severity5.4NVD Advisory· Published May 21, 2026· Updated May 21, 2026
CVE-2026-48216
CVE-2026-48216
Description
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the multiple POST parameters (ticketshost, ticketsdb, ticketsuser, ticketspassword, ticketsprefix, db_schema) directly into HTML form input value attributes. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <3.44.2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.