Information Disclosure Vulnerability in OTRS by OTRS AG
CVE-2025-24391
What is CVE-2025-24391?
A significant information disclosure vulnerability exists in the OTRS system's External Interface. This flaw allows an attacker to glean the presence of user accounts by analyzing various HTTP response codes and messages. By exploiting this vulnerability, unauthorized users can systematically discover valid email addresses associated with accounts in affected versions of OTRS. This could lead to further security breaches, making it crucial for organizations using OTRS 7.0.X, 8.0.X, 2023.X, 2024.X, or 2025.X to apply necessary security updates and safeguard their user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OTRS 7.0.x
OTRS 7.0.x
OTRS 8.0.x
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
