CVE-2025-24388: Unsafe handling of AJAX calls
A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user.
This issue affects:
OTRS 7.0.X
OTRS 8.0.X OTRS 2023.X OTRS 2024.X OTRS 2025.X
((OTRS)) Community Edition: 6.0.x
Products based on the ((OTRS)) Community Edition also very likely to be affected
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24388?
CVE-2025-24388 is considered a high severity vulnerability due to parameter injection issues in OTRS.
How do I fix CVE-2025-24388?
To fix CVE-2025-24388, upgrade to OTRS version 8.0.0 or later.
Which versions of OTRS are affected by CVE-2025-24388?
CVE-2025-24388 affects OTRS versions 7.0.X, 8.0.X, 2023.X, 2024.X, and 2025.X before the patch.
Who is impacted by CVE-2025-24388?
Authenticated agent or admin users are impacted by CVE-2025-24388 due to potential parameter injection.
Is there a known exploit for CVE-2025-24388?
As of now, there are no public reports of an active exploit for CVE-2025-24388.