CVE-2026-48243

Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public source repository. Any actor with read access to the source tree can extract the key and use it to make third-party API calls billed to or rate-limited against the original owner's WhitePages account.
Configurations

No configuration.

History

20 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) Open ISES Tickets antes de la versión 3.44.2 incrusta una clave API de WhitePages para búsqueda inversa de teléfonos, codificada de forma rígida, en wp1.PHP, que está subida al repositorio de código fuente público. Cualquier actor con acceso de lectura al árbol de código fuente puede extraer la clave y usarla para realizar llamadas a la API de terceros facturadas a la cuenta de WhitePages del propietario original o con límite de tasa aplicado a esta.

21 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 18:16

Updated : 2026-07-20 20:10


NVD link : CVE-2026-48243

Mitre link : CVE-2026-48243

CVE.ORG link : CVE-2026-48243


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials