A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses.
This issue affects:
* OTRS 7.0.X
* OTRS 8.0.X
* OTRS 2023.X
* OTRS 2024.X
* OTRS 2025.X
Metrics
Affected Vendors & Products
References
History
Mon, 28 Jul 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Otrs
Otrs otrs |
|
| Vendors & Products |
Otrs
Otrs otrs |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Mon, 14 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Jul 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X | |
| Title | Possible user enumeration | |
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OTRS
Published: 2025-07-14T08:15:58.668Z
Updated: 2025-07-14T12:58:02.638Z
Reserved: 2025-01-21T09:09:58.721Z
Link: CVE-2025-24391
Updated: 2025-07-14T12:57:53.315Z
Status : Awaiting Analysis
Published: 2025-07-14T09:15:23.593
Modified: 2025-07-15T13:14:24.053
Link: CVE-2025-24391
No data.