• Deutsch
  • English
  • Login
+49 (0)9427 68 39 000
OTOBO
  • SOFTWARE
    • Software | Overview
    • IT Service Management
    • Customer Service Management
    • Enterprise Service Management
    • Demo
    • Download
    • Documentation
  • SERVICES
    • Overview | Services
    • Consulting
    • Training
    • Customizing
    • OTRS Migration to OTOBO
    • Support
    • Managed Services
    • Support Portal
  • COMPANY
    • About us
    • Carreers
    • Partner
    • Contact us
    • Newsletter
  • RESOURCES
  • COMMUNITY
    • Open Source
    • Community Forum
    • Download
    • Documentation
    • Translate OTOBO
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

SECURITY ADVISORY

OTOBO 10.1.8 – Security Patch

  • DESCRIPTION
  • MEASURES FOR SECURE OPERATION
  • BUG FIXES
  • DOWNLOADS
  • PUBLISHED:
  • RELEASE TYPE:
  • CRITICALITY:
  • AFFECTED VERSIONS:
  • REFERENCE:
  • OCTOBER 05, 2023
  • Security Patch Release
  • MEDIUM
  • OTOBO 10.1
  • https://nvd.nist.gov/vuln/detail/CVE-2023-5421

Injecting JavaScript code through customer management

Description

Problem

  • XSS Vulnerability: An attacker logged in as a user with permissions to create and modify customer data could manipulate the CustomerID field to execute JavaScript code, which would be executed immediately after saving the data. This issue only occurs if the AdminCustomerUser::UseAutoComplete configuration was previously changed.

Special thanks to Tim Püttmanns (maxence) for bringing this vulnerability to our attention.

Potential Consequences

JS code execution occurs immediately after save.

Measure for secure operation

Update to OTOBO 10.1.8

A security patch is now available to address this issue. Please upgrade your system to ensure protection.

➞ Download Security Patch Package

Bug Fixes

  • [Enhancement] Added an optional leeway, i.e., a buffer for timestamp verification during OpenID Connect authentication.
  • [Translation] Translations into Arabic (Saudi Arabia), German, French, Japanese, Norwegian, Polish, and Russian. Thanks to the community.
  • [bugfix] Fixed an error where customers were prompted to change their password in the agent interface via AdminCustomerUser after modifying their data.
  • [bugfix] Corrected the usage of the ‘AuthSyncModule::LDAP::GroupDN’ option.
  • [bugfix] Enabled the use of dynamic fields in ElasticSearch searches. Special thanks to wetzf for the pull request.
  • [bugfix] Hid the response toggle button in CustomerTicketZoom for closed tickets that cannot be reopened.
  • [bugfix] Fixed an error in SysConfig, which restricted the functionality of keys with ### in the frontend.

Have a question? We’re here to help. Drop us a line.

Contact

As a support customer, you require assistance with the security patch. Please contact us through your access in the support portal.

Downloads

Security Patch Update

Download

Administrator manual

Download

Installation guideline

Download

Developer manual

Download
Search Search

Filter by

  • Add-On Feature
  • Article
  • Case Studies
  • News
  • Release Notes
  • Security Patch

Reset filter

Newsletter | Subscribe to receive news and updates from OTOBO

Company

About us
Careers
Job Opportunities
Become a Partner
Contact us
Newsletter

OTOBO | Simplify work and create exceptional service experiences.

The Source Code Owner and Maintainer of OTOBO.

Software

Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation

Report a security issues:
security@otobo.org

Services

Support Portal
Consulting
Training
Support
Managed Services
Customizing
OTRS Migration
Find a Partner

Community

Open Source
Community Forum
Contribute
OTOBO Developer
OTOBO@GitHub

© 2026 Rother OSS GmbH | All rights reserved.
  • Cookie settings
  • Imprint
  • Privacy Policy
  • Disclaimer
Link to: OTOBO-10.0.19 Link to: OTOBO-10.0.19 OTOBO-10.0.19OTOBO Security Patch Link to: Add-On Feature – Rocket.Chat-Integration Link to: Add-On Feature – Rocket.Chat-Integration OTOBO Add-On FeatureAdd-On Feature – Rocket.Chat-Integration
Scroll to top Scroll to top Scroll to top