CVE-2025-24387
A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive
cookie sett
A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation. This issue affects: OTRS 7.0.X OTRS 8.0.X OTRS 2023.X OTRS 2024.X * OTRS 2025.x.
MEDIUM · CVSS 4.8
EPSS 0.00081
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0