SECURITY ADVISORY
- PUBLISHING DATE:
- RELEASE TYPE:
- CRITICALITY:
- AFFECTED VERSION:
- May 06, 2025
- Security Patch Release
- HIGH
- OTOBO 11.0
Description
- [Security | high] Privilege escalation vulnerability resolved (CVE-2025-43926)
Thanks to a report by Tim Püttmanns (maxence), a potential security vulnerability has been fixed. This update enhances the security of your OTOBO environment and helps prevent unauthorized access. After updating the core, please ensure that all affected add-ons are updated via the package manager.
Enhancements
- [Enhancement] The ticket search now supports searching for selected subfields of the Dynamic Field Set – making it easier to find specific information. [#4261]
- [Enhancement] A new option (Ticket::Frontend::AsteriskExplanation) allows to display an explanatory note at the top of forms: “Fields marked with * are mandatory.” – This promotes accesssibility. [#3954]
Bug Fixes
- [Bugfix] Resolved an issue in the customer ticket form where ticket creation failed if a DateTime field was hidden and past dates were not allowed. [#4238]
- [Bugfix] Fixed missing translations for dynamic field titles on mouse hover – titles are now displayed correctly. [#4196]
- [Bugfix] Fixed an issue where the dynamic field TicketReference did not correctly find ticket numbers. [#4303]
- [Bugfix] Fixed an error that occurred when clearing the dynamic field Database in multiselect mode. [#4301]
Next steps
Update to OTOBO 11.0.9
We recommend that you fix the vulnerabilities and benefit from the latest improvements. Please update your system.
Security patch? System update?
No need to handle it alone.
As a support customer, just reach out via our portal or give us a quick call – we’re here to help.
Haven’t worked with us yet? Maybe now’s the perfect time. We’ll be happy to support your next update. Just get in touch – we’d love to hear from you!
Company
OTOBO | Simplify work and create exceptional service experiences.
The Source Code Owner and Maintainer of OTOBO.
Software
Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation
Report a security issues:
security@otobo.org