Session Hijacking Vulnerability in OTRS Application Server
CVE-2025-24390
6.8MEDIUM
What is CVE-2025-24390?
The OTRS Application Server contains a vulnerability that allows session hijacking due to the absence of certain attributes in the cookie settings for HTTPS sessions. This flaw affects multiple versions of OTRS, including 7.0.X, 8.0.X, 2023.X, and 2024.X, potentially compromising sensitive user sessions if not promptly addressed. Administrators are advised to implement security best practices and review the cookie settings to enhance session security.
Affected Version(s)
OTRS 7.0.x
OTRS 7.0.x
OTRS 8.0.x
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Special thanks to Alissa Kim for reporting this vulnerability.