6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public source repository. Any actor with read access to the source tree can extract the key and use it to make third-party API calls billed to or rate-limited against the original owner's WhitePages account.
Basic Information
ID
CVE-2026-48243
Source
VulnCheck
Published
May 21, 2026 at 17:11
Affected Product
Vendor
Open ISES
Product
Tickets
Affected Versions
Open ISES Tickets 0