216.73.216.6

CVE-2025-24391

· Published 14/07/2025 09:15 · Modified 15/07/2025 13:14

Labels: CVE-2025-24391 2025-07-14CVE-2025-24391CWE-203[email protected]

Essential information

Published
14/07/2025 09:15
Modified
15/07/2025 13:14
Author
Creator
CVSS
5.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
otrs / otrs cpe:2.3:a:otrs:otrs:7.0.*:*:*:*:*:*:*:*
otrs / otrs cpe:2.3:a:otrs:otrs:8.0.*:*:*:*:*:*:*:*
otrs / otrs cpe:2.3:a:otrs:otrs:2023.*:*:*:*:*:*:*:*
otrs / otrs cpe:2.3:a:otrs:otrs:2024.*:*:*:*:*:*:*:*
otrs / otrs cpe:2.3:a:otrs:otrs:2025.*:*:*:*:*:*:*:*

References