Description

A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X

INFO

Published Date :

2025-07-14T08:15:58.668Z

Last Modified :

2025-07-14T12:58:02.638Z

Source :

OTRS
AFFECTED PRODUCTS

The following products are affected by CVE-2025-24391 vulnerability.

Vendors Products
Otrs
  • Otrs
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-24391.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact