HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-48242 — Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection cre...

·Source: NIST NVD

Updated:

Executive Summary

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the source to obtain valid configuration values that may match deployed installations.

Analysis

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the source to obtain valid configuration values that may match deployed installations. CVSS Score: 8.1. Published: 2026-05-21T18:16:21.220.

Indicators of Compromise (1)

CVE (1)
CVE-2026-48242
Source Attribution

Originally published by NIST NVD on May 21, 2026. Verified by: NIST.

Related Threats