CVE-2026-48234 | openises Tickets up to 3.44.1 SELECT Statement list_requests.php sort/dir sql injection
A vulnerability marked as critical has been reported in openises Tickets up to 3.44.1. Affected by this issue is some unknown functionality of the file portal/ajax/list_requests.php of the component SELECT Statement Handler. This manipulation of the argument sort/dir causes sql injection.
This vulnerability is tracked as CVE-2026-48234. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More