CVE-2025-24391 - CVE House
Back to Database
Status published Medium CVE-2025-24391

Possible user enumeration

Vulnerability Description

A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-24391

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Special thanks to David Silva for reporting this vulnerability.

Affected Vendor

Affected Software

OTRS
Vulnerable Versions:
7.0.x, 8.0.x, 2023.x, 2024.x, 2025.x

Timeline

Official Publish: July 14th, 2025
Last Modified: July 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)