First published: Mon Dec 19 2022(Updated: )
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1, from 8.0.1 before 8.0.28 Patch 1; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
Credit: security@otrs.com security@otrs.com
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=6.0.1<=6.0.34 | |
Otrs Otrs | >=7.0.1<7.0.40 | |
Otrs Otrs | >=8.0.1<8.0.28 | |
Otrs Otrs | =7.0.40 | |
Otrs Otrs | =8.0.28 |
Update to OTRS 7.0.40 Patch 1 or OTRS 8.0.28 Patch 1 released on 19th December 2022
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this OTRS vulnerability is CVE-2022-4427.
CVE-2022-4427 has a severity rating of 9.8 (Critical).
OTRS versions 6.0.1 through 6.0.34, OTRS versions 7.0.1 through 7.0.40 Patch 1, and OTRS versions 8.0.1 through 8.0.28 Patch 1 are affected by CVE-2022-4427.
CVE-2022-4427 allows SQL Injection via TicketSearch Webservice in OTRS.
More information about CVE-2022-4427 can be found at the following references: [1](https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html), [2](https://otrs.com/release-notes/otrs-security-advisory-2022-15/).