Sprache wechseln auf deutsch
Znuny Professional Services

The ((OTRS)) Community Edition Fork with long-term Support (LTS)

Overview

ZSA-2026-15

A SQL injection vulnerability exists in the ticket search (Kernel::System::Ticket::TicketSearch and Kernel::System::Ticket::ArticleSearchIndex::DB) via the ContentSearch parameter. The parameter is expected to be either "AND" or "OR", but its value was concatenated directly into the generated SQL query without validation.

Fixed in: Znuny LTS 6.5.25 and Znuny 7.3.7

Thanks for reporting to Mokrane ABDELMALEK (via the Ghent University VDP programme).