CVE-2026-48244
Open ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in settings.inc.php
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.9EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
21 may 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Google Cloud project.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
Open ISES · Tickets¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →