• Deutsch
  • English
  • Login
+49 (0)9427 68 39 000
OTOBO
  • SOFTWARE
    • Software | Overview
    • IT Service Management
    • Customer Service Management
    • Enterprise Service Management
    • Demo
    • Download
    • Documentation
  • SERVICES
    • Overview | Services
    • Consulting
    • Training
    • Customizing
    • OTRS Migration to OTOBO
    • Support
    • Managed Services
    • Support Portal
  • COMPANY
    • About us
    • Carreers
    • Partner
    • Contact us
    • Newsletter
  • RESOURCES
  • COMMUNITY
    • Open Source
    • Community Forum
    • Download
    • Documentation
    • Translate OTOBO
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

SECURITY ADVISORY

OTOBO 10.1.6 Security Patch

  • DESCRIPTION
  • MEASURES FOR SECURE OPERATION
  • BUG FIXES
  • DOWNLOADS
  • PUBLISHED:
  • RELEASE TYPE:
  • CRITICALITY:
  • AFFECTED VERSIONS:
  • REFERENCE:
  • December 20, 2022
  • Security Patch Release
  • MEDIUM
  • OTOBO 10.1
  • https://nvd.nist.gov/vuln/detail/CVE-2022-4427

Description

Problem

  • SQL Injection: We fixed a vulnerability that allowed attackers to inject SQL code through the “TicketSearch” web service operation.
  • JS Injection: Additionally, we patched a vulnerability that enabled attackers with OTOBO admin rights to inject JS code.

Special thanks to Tim Püttmanns (maxence) for reporting these vulnerabilities.

Potential Consequences

  • Injection of SQL / JS Code

Measures for secure operation

Update to OTOBO 10.1.6

A security patch update is available to fix the vulnerability. Please update your system.

➞ Download Security Patch Package

Bug Fixes

  • [Enhancement] Script to resolve utf8/utf8mb3 issues for solving a specific migration problem
  • [Enhancement] Fixed problems with ConfigurationDeploySync in S3 environments
  • [Enhancement] Fixed a bug that caused high CPU load due to SystemConfigurationOutOfSyncCheck notification
  • [Bugfix] Terminal notifications are now sent even when display is enabled for customers
  • [Bugfix] Corrected the ‘Printed by’ information when printing company tickets in the CustomerTicketOverview. Instead of showing the ticket owner, it now displays the person who triggered the print.
  • [Bugfix] Adjusted hidden filters in Medium and Preview views in TicketOverview
  • [Bugfix] Adjusted formatting options for images in CKEditor. Embedded graphics in signatures can now be correctly formatted.
  • [Bugfix] Fixed a rare bug that caused errors in AjaxAttachments display
  • [Bugfix] Corrected settings in migration.pl for Package::RepositoryRoot
  • [Bugfix] Fixed an error in CustomerFrontend::Navigation###ExternalURLJump###1
  • [Enhancement] Created a new Docker file otobo.kerberos.web.docker
  • [Bugfix] Fixed a rare bug where sender email addresses were not correctly displayed
  • [Bugfix] HTTP Redirect for OTOBO_WEB_HTTPS_PORT fixed
  • [Bugfix] Generic Agent now sends SendNoNotification consistently for all subsequent events. Notifications were occasionally not sent when events were triggered by GenericAgents.
  • [Bugfix] base64 decoding of CLOB columns during migration from Oracle to MariaDB
  • [Bugfix] Fixed a bug in the source DB name check during Oracle migration.
  • Fixed Perl 5.34 shmwrite problem in OTOBO 10

We’re happy to answer your questions. Contact us.

Contact

You are a support customer and need assistance with the security patch. Please contact us through your access in the support portal.

Downloads

Security Patch Update

Download

Administrator manual

Download
Download

Developer manual

Download
Search Search

Filter by

  • Add-On Feature
  • Article
  • Case Studies
  • News
  • Release Notes
  • Security Patch

Reset filter

Newsletter | Subscribe to receive news and updates from OTOBO

Company

About us
Careers
Job Opportunities
Become a Partner
Contact us
Newsletter

OTOBO | Simplify work and create exceptional service experiences.

The Source Code Owner and Maintainer of OTOBO.

Software

Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation

Report a security issues:
security@otobo.org

Services

Support Portal
Consulting
Training
Support
Managed Services
Customizing
OTRS Migration
Find a Partner

Community

Open Source
Community Forum
Contribute
OTOBO Developer
OTOBO@GitHub

© 2026 Rother OSS GmbH | All rights reserved.
  • Cookie settings
  • Imprint
  • Privacy Policy
  • Disclaimer
Link to: OAuth2 replaces Microsoft standard authentication Link to: OAuth2 replaces Microsoft standard authentication OAuth2 replaces Microsoft standard authenticationOTOBO News Link to: OTOBO 10.0.17 Link to: OTOBO 10.0.17 OTOBO Security PatchOTOBO 10.0.17
Scroll to top Scroll to top Scroll to top