Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 22 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openises
Openises tickets |
|
| Vendors & Products |
Openises
Openises tickets |
Thu, 21 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database if it is reachable from their network. | |
| Title | Open ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in loader.php | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-21T18:03:27.977Z
Reserved: 2026-05-21T13:15:18.101Z
Link: CVE-2026-48241
Updated: 2026-05-21T18:03:21.470Z
Status : Deferred
Published: 2026-05-21T18:16:21.070
Modified: 2026-06-17T10:54:59.047
Link: CVE-2026-48241
No data.
OpenCVE Enrichment
Updated: 2026-05-22T12:30:27Z