This issue affects:
* OTRS 7.0.X
* OTRS 8.0.X
* OTRS 2023.X
* OTRS 2024.X
* OTRS 2025.X
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21322 | A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X |
Solution
Update to OTRS 2025.6.1. or later. Please note that there will be no OTRS 7 patches
Workaround
No workaround given by the vendor.
Mon, 28 Jul 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Otrs
Otrs otrs |
|
| Vendors & Products |
Otrs
Otrs otrs |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Mon, 14 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Jul 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X | |
| Title | Possible user enumeration | |
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2025-07-14T12:58:02.638Z
Reserved: 2025-01-21T09:09:58.721Z
Link: CVE-2025-24391
Updated: 2025-07-14T12:57:53.315Z
Status : Awaiting Analysis
Published: 2025-07-14T09:15:23.593
Modified: 2025-07-15T13:14:24.053
Link: CVE-2025-24391
No data.
OpenCVE Enrichment
Updated: 2025-07-28T12:46:01Z
EUVD