CVE-2026-48238: Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id Parameter
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.php where the id GET parameter is concatenated into the WHERE clause of a SELECT statement used as a ticket-existence sanity check without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.
Security readout for executives and security teams
Plain-English summary
Open ISES Tickets versions before 3.44.2 allow a logged-in attacker to manipulate a database query through a web request. Successful abuse could expose sensitive ticket data or alter or destroy database contents. The issue is remotely reachable when the affected endpoint is accessible.
Executive priority
Prioritize remediation promptly for production systems, especially those containing sensitive tickets or reachable from untrusted networks. Authentication reduces exposure but does not justify delay because compromised or ordinary low-privileged accounts may be sufficient.
Technical view
CVE-2026-48238 is a CWE-89 SQL injection in ajax/mobile_main.php. The id GET parameter is concatenated into a SELECT statement’s WHERE clause without sanitization. Exploitation requires authenticated, low-privileged access, needs no user interaction, and can change query semantics. CVSS 4.0 rates it 7.1.
Likely exposure
Exposure is likely where Open ISES Tickets before 3.44.2 is deployed and authenticated users can reach ajax/mobile_main.php. Internet exposure increases opportunity, but authentication remains required. The bundle’s structured affected entry is inconsistent, listing version "0" as unaffected; confirm installed versions directly.
Exploitation context
The provided sources do not establish active exploitation, and this CVE is not identified as KEV in the bundle. However, low attack complexity, network reachability, and limited privilege requirements make exploitation plausible where an attacker obtains a valid account.
Researcher notes
The named fix is release 3.44.2, supported by a public patch commit. Testing should remain non-destructive and focus on version, code-path, log, and database-audit verification. The bundle does not provide evidence of exploitation in the wild. Its structured version metadata conflicts with the narrative affected range.
Mitigation direction
Upgrade Open ISES Tickets to version 3.44.2 or later.
Review the vendor release notes and patch commit before deployment.
Restrict access to the affected application until upgrading is complete.
Rotate database credentials if investigation indicates unauthorized query activity.
Validation and detection
Inventory Open ISES Tickets deployments and record their exact versions.
Confirm every deployment runs version 3.44.2 or later.
Verify the vendor patch is present in any custom or forked build.
Review authentication and application logs for suspicious requests targeting ajax/mobile_main.php.
Assess database audit records for unexpected reads, changes, or deletions.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-89: Database access and collection lookup
Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-89 · source CWE mapping
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.