A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses.
This issue affects:
* OTRS 7.0.X
* OTRS 8.0.X
* OTRS 2023.X
* OTRS 2024.X
* OTRS 2025.X
Metrics
Affected Vendors & Products
References
History
Mon, 28 Jul 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Otrs
Otrs otrs |
|
Vendors & Products |
Otrs
Otrs otrs |
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Mon, 14 Jul 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 14 Jul 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X | |
Title | Possible user enumeration | |
Weaknesses | CWE-203 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: OTRS
Published: 2025-07-14T08:15:58.668Z
Updated: 2025-07-14T12:58:02.638Z
Reserved: 2025-01-21T09:09:58.721Z
Link: CVE-2025-24391

Updated: 2025-07-14T12:57:53.315Z

Status : Awaiting Analysis
Published: 2025-07-14T09:15:23.593
Modified: 2025-07-15T13:14:24.053
Link: CVE-2025-24391

No data.