• Deutsch
  • English
  • Login
+49 (0)9427 68 39 000
OTOBO
  • SOFTWARE
    • Software | Overview
    • IT Service Management
    • Customer Service Management
    • Enterprise Service Management
    • Demo
    • Download
    • Documentation
  • SERVICES
    • Overview | Services
    • Consulting
    • Training
    • Customizing
    • OTRS Migration to OTOBO
    • Support
    • Managed Services
    • Support Portal
  • COMPANY
    • About us
    • Carreers
    • Partner
    • Contact us
    • Newsletter
  • RESOURCES
  • COMMUNITY
    • Open Source
    • Community Forum
    • Download
    • Documentation
    • Translate OTOBO
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

SECURITY ADVISORY

OTOBO 10.0.19 – Security Patch

  • DESCRIPTION
  • MEASURES FOR SECURE OPERATION
  • BUG FIXES
  • DOWNLOADS

Injecting custom JS code through customer management

  • PUBLISHED:
  • RELEASE TYPE:
  • CRITICALITY:
  • AFFECTED VERSIONS:
  • REFERENCE:
  • October 05,.2023
  • Security Patch Release
  • MEDIUM
  • OTOBO 10.0
  • https://nvd.nist.gov/vuln/detail/CVE-2023-5421

Description

Problem

  • XSS Vulnerability: An attacker logged in as a user with permissions to create and modify customer data could manipulate the CustomerID field to execute JavaScript code, which would be executed immediately after saving the data. This issue only occurs if the AdminCustomerUser::UseAutoComplete configuration was changed previously.
  • Header Injection Fix: We have addressed a vulnerability that allowed header injection via web services in systems where these were enabled.

Special thanks to Tim Püttmanns (maxence) for bringing these vulnerabilities to our attention.

Potential Consequences

  • Immediate JavaScript code execution after save.
  • Web service header injection vulnerability.

Measures for secure operation

Update to OTOBO 10.0.19

A security patch is now available to address this issue. Please upgrade your system to ensure protection.

➞ Download Security Patch Package

Bug Fixes

  • [Enhancement] Added an optional leeway, i.e., a buffer for timestamp verification during OpenID Connect authentication.
  • [bugfix] Fixed an error where customers were prompted to change their password in the agent interface via AdminCustomerUser after modifying their data.
  • [bugfix] Corrected the usage of the ‘AuthSyncModule::LDAP::GroupDN’ option.
  • [bugfix] Enabled the use of dynamic fields in ElasticSearch searches. Special thanks to wetzf for the pull request.

Have a question? We’re here to help. Drop us a line.

Contact

If you’re a support customer and need help with the security patch, please reach out to us through your support portal login.

Downloads

Security Patch Update

Download

Administrator manual

Download

Installation guideline

Download

Developer manual

Download
Search Search

Filter by

  • Add-On Feature
  • Article
  • Case Studies
  • News
  • Release Notes
  • Security Patch

Reset filter

Newsletter | Subscribe to receive news and updates from OTOBO

Company

About us
Careers
Job Opportunities
Become a Partner
Contact us
Newsletter

OTOBO | Simplify work and create exceptional service experiences.

The Source Code Owner and Maintainer of OTOBO.

Software

Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation

Report a security issues:
security@otobo.org

Services

Support Portal
Consulting
Training
Support
Managed Services
Customizing
OTRS Migration
Find a Partner

Community

Open Source
Community Forum
Contribute
OTOBO Developer
OTOBO@GitHub

© 2026 Rother OSS GmbH | All rights reserved.
  • Cookie settings
  • Imprint
  • Privacy Policy
  • Disclaimer
Link to: OTOBO 10.1.7 Link to: OTOBO 10.1.7 OTOBO 10.1.7OTOBO Patch Release Link to: OTOBO 10.1.8 Link to: OTOBO 10.1.8 OTOBO Security PatchOTOBO 10.1.8
Scroll to top Scroll to top Scroll to top