Vulnerability Description
A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.x
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Otrs | Otrs | >= 7.0.0, <= 2025.1.2 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-24387?
CVE-2025-24387 is a vulnerability with a CVSS score of 4.8 (MEDIUM). A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious ...
How severe is CVE-2025-24387?
CVE-2025-24387 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24387?
Check the references section above for vendor advisories and patch information. Affected products include: Otrs Otrs.