Information Disclosure Vulnerability in OTRS by OTRS AG
CVE-2025-24391
5.3MEDIUM
What is CVE-2025-24391?
A significant information disclosure vulnerability exists in the OTRS system's External Interface. This flaw allows an attacker to glean the presence of user accounts by analyzing various HTTP response codes and messages. By exploiting this vulnerability, unauthorized users can systematically discover valid email addresses associated with accounts in affected versions of OTRS. This could lead to further security breaches, making it crucial for organizations using OTRS 7.0.X, 8.0.X, 2023.X, 2024.X, or 2025.X to apply necessary security updates and safeguard their user data.
Affected Version(s)
OTRS 7.0.x
OTRS 7.0.x
OTRS 8.0.x
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Special thanks to David Silva for reporting this vulnerability.