• Deutsch
  • English
  • Login
+49 (0)9427 68 39 000
OTOBO
  • SOFTWARE
    • Software | Overview
    • IT Service Management
    • Customer Service Management
    • Enterprise Service Management
    • Demo
    • Download
    • Documentation
  • SERVICES
    • Overview | Services
    • Consulting
    • Training
    • Customizing
    • OTRS Migration to OTOBO
    • Support
    • Managed Services
    • Support Portal
  • COMPANY
    • About us
    • Carreers
    • Partner
    • Contact us
    • Newsletter
  • RESOURCES
  • COMMUNITY
    • Open Source
    • Community Forum
    • Download
    • Documentation
    • Translate OTOBO
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

SECURITY ADVISORY

OTOBO 10.0.20 Security Patch

  • DESCRIPTION
  • MEASURES FOR SECURE OPERATION
  • BUG FIXES
  • DOWNLOADS

Injection of JS Code via Customer Management

  • PUBLISHED:
  • RELEASE TYPE:
  • CRITICALITY:
  • AFFECTED VERSIONS:
  • REFERENCE:
  • March 27, 2024
  • Security Patch Release
  • LOW
  • OTOBO 10.0
  • —

Description

Problem

  • We fixed a vulnerability that allowed external content to be displayed in the ticket detail view without the user’s active consent. OTOBO is now much more stringent overall in its handling of HTML, which is displayed in articles, for example.

Many thanks to Tim Püttmanns (maxence), who brought this vulnerability to our attention.

Potential Consequences

  • Display of External Content in Ticket Details Without Active Consent

Measures for Secure Operation

Update to OTOBO 10.0.20

A security patch update is available to fix the vulnerability. Please update your system.

➞ Download Security Patch Package

Bug Fixes

  • [Security Enhancement] Update to CKEditor Version 4.22.1
  • [Security Enhancement] Javascript tags are now filtered out of links
  • [Bugfix] Fixed a bug that caused incorrect ticket attributes to be used in ACLs after ticket creation in some cases
  • [Bugfix] Fixed an error that prevented standard values from being displayed correctly in dynamic fields on many masks
  • and more (Changes)

We’re happy to answer your questions. Contact us.

Contact

You’re a support customer and need assistance with the security patch. Please contact us through your access in the support portal.

Downloads

Security Patch Update

Download

Administrator manual

Download

Installation guideline

Download

Developer manual

Download
Search Search

Filter by

  • Add-On Feature
  • Article
  • Case Studies
  • News
  • Release Notes
  • Security Patch

Reset filter

Newsletter | Subscribe to receive news and updates from OTOBO

Company

About us
Careers
Job Opportunities
Become a Partner
Contact us
Newsletter

OTOBO | Simplify work and create exceptional service experiences.

The Source Code Owner and Maintainer of OTOBO.

Software

Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation

Report a security issues:
security@otobo.org

Services

Support Portal
Consulting
Training
Support
Managed Services
Customizing
OTRS Migration
Find a Partner

Community

Open Source
Community Forum
Contribute
OTOBO Developer
OTOBO@GitHub

© 2026 Rother OSS GmbH | All rights reserved.
  • Cookie settings
  • Imprint
  • Privacy Policy
  • Disclaimer
Link to: OTOBO 10.1.9 Link to: OTOBO 10.1.9 OTOBO 10.1.9OTOBO Security Patch Link to: Perl Services, Riedstadt, Germany Link to: Perl Services, Riedstadt, Germany OTOBO Partner Perl Services LogoPerl Services, Riedstadt, Germany
Scroll to top Scroll to top Scroll to top