


Perceptive Security
SOC/SIEM Consultancy

The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting maliciou…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 17:11:07
Source:
nvd.nist.gov
Web Technologies, Database & Storage
The Open ISES Project version 3.30A contains a critical SQL injection vulnerability in the add_facnote.php file. Unauthenticated attackers can exploit this vulnerability by injecting malicious SQL code through the ticket_id parameter via GET requests. The vulnerability allows attackers to execute arbitrary SQL queries and extract sensitive database information including version details and other confidential data. This represents a significant security risk as it requires no authentication and can lead to complete database compromise.
Technical details
Mitigation steps:
Affected products:
Open ISES Project
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25404
http://openises.sourceforge.net/
https://sourceforge.net/projects/openises/files/latest/download
https://www.exploit-db.com/exploits/45645
https://www.vulncheck.com/advisories/the-open-ises-project-3-30a-sql-injection-via-add-facnote-php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
