VYPR

OTRS Application Server

by OTRS

CVEs (1)

  • CVE-2025-24387MedMar 10, 2025
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read…