OTRS
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*
- ~6.0
A vulnerability exists in OTRS and OTRS Community Edition that involves the absence of the X-Content-Type-Options HTTP response header, which is crucial for preventing MIME type sniffing. This flaw allows an attacker to upload or insert content that could be misinterpreted as a different MIME type than intended. The vulnerability affects OTRS versions 7.0.X, 8.0.X, 2023.X, and 2024.X, as well as OTRS Community Edition 6.0.x. Additionally, products based on OTRS Community Edition are likely affected.
Exploitation of this vulnerability could lead to content spoofing, where uploaded or inserted content is misrepresented due to incorrect MIME type handling.
Users are advised to update to OTRS version 2025.1.x. Note that there will be no patches for OTRS 7.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.