Back to CVE List

CVE-2026-48244

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Vulnerability Description

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Google Cloud project.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-798
Source
NVD
Vendor
Open ISES
Product
Tickets

External References

Discussion (0)

Add Comment

No comments yet. Be the first!