Anwendungssicherheit

🟡 CVE-2026-1815: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-1815: Medium Schwachstelle

Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking. This issue affects Mobile Application:...

23. Mai 2026 Keine Kommentare
🟡 CVE-2026-48249: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-48249: Medium Schwachstelle

Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST)...

23. Mai 2026 Keine Kommentare
🟡 CVE-2026-48248: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-48248: Medium Schwachstelle

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST)...

23. Mai 2026 Keine Kommentare
🟡 CVE-2026-48247: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-48247: Medium Schwachstelle

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST)...

23. Mai 2026 Keine Kommentare
🟡 CVE-2026-48246: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-48246: Medium Schwachstelle

Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST)...

23. Mai 2026 Keine Kommentare
🟡 CVE-2026-1816: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-1816: Medium Schwachstelle

Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue...

23. Mai 2026 Keine Kommentare
🟠 CVE-2026-48240: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48240: High Schwachstelle

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id and f_tick_id POST parameters are...

23. Mai 2026 Keine Kommentare
🟠 CVE-2026-48239: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48239: High Schwachstelle

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the tick_id POST parameter is concatenated into...

23. Mai 2026 Keine Kommentare
🟠 CVE-2026-48238: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48238: High Schwachstelle

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.php where the id GET parameter is concatenated into...

23. Mai 2026 Keine Kommentare
🟠 CVE-2026-48237: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48237: High Schwachstelle

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_ticket_id and frm_resp_id POST parameters are...

23. Mai 2026 Keine Kommentare