cvedb.io
CVE-2026-48244
MEDIUM · CVSS 5.3
EPSS exploitation probability: 0%
Published 2026-05-21T18:16:21.530 · Last modified 2026-06-17T10:54:59.403

Summary

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Google Cloud project.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.