CVE-2025-24391: Possible user enumeration
Published Jul 14, 2025
·Updated
A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses.
This issue affects:
OTRS 7.0.X
OTRS 8.0.X OTRS 2023.X OTRS 2024.X OTRS 2025.X
Affected Software
1 affected component
OTRS OTRS>=7.0.0, >=8.0.0, >=2023.0, >=2024.0, >=2025.0
Remediation
Information
Update to OTRS 2025.6.1. or later. Please note that there will be no OTRS 7 patches
Event History
Jul 14, 2025
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24391?
CVE-2025-24391 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2025-24391?
To fix CVE-2025-24391, upgrade to OTRS version 8.0.0 or later.
3
What impact does CVE-2025-24391 have on OTRS?
CVE-2025-24391 allows attackers to infer the existence of user accounts through HTTP response messages.
4
Which versions of OTRS are affected by CVE-2025-24391?
OTRS versions 7.0.X through 2025.0 are affected by CVE-2025-24391.
5
Can CVE-2025-24391 lead to account enumeration?
Yes, CVE-2025-24391 can lead to account enumeration by exposing valid email addresses.