GHSA-5hxh-6mg6-f5mhCriticalCVSS 8.1
Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host,...
🔗 CVE IDs covered (1)
📋 Description
Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the source to obtain valid configuration values that may match deployed installations.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-48242
- https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a9f2dbff
- https://github.com/openises/tickets/releases/tag/v3.44.2
- https://www.vulncheck.com/advisories/open-ises-tickets-hardcoded-mysql-credentials-in-import-mdb-php
- https://github.com/advisories/GHSA-5hxh-6mg6-f5mh