CVE-2022-4427: SQL Injection via OTRS Search API
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1, from 8.0.1 before 8.0.28 Patch 1; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this OTRS vulnerability?
The vulnerability ID for this OTRS vulnerability is CVE-2022-4427.
What is the severity rating of CVE-2022-4427?
CVE-2022-4427 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2022-4427?
OTRS versions 6.0.1 through 6.0.34, OTRS versions 7.0.1 through 7.0.40 Patch 1, and OTRS versions 8.0.1 through 8.0.28 Patch 1 are affected by CVE-2022-4427.
How does CVE-2022-4427 impact OTRS?
CVE-2022-4427 allows SQL Injection via TicketSearch Webservice in OTRS.
Where can I find more information about CVE-2022-4427?
More information about CVE-2022-4427 can be found at the following references: [1](https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html), [2](https://otrs.com/release-notes/otrs-security-advisory-2022-15/).