OTRS
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*
- ~7.0
- ~8.0
- ~2023
- ~2024
- ~2025
A session hijacking vulnerability has been identified in OTRS Application Server. This issue arises from missing attributes in cookie settings for HTTPS sessions, allowing authentication cookies to be sent from a potentially malicious website to an OTRS endpoint. As a result, unauthorized read operations could be performed. The vulnerability affects OTRS versions 7.0.X, 8.0.X, 2023.X, 2024.X, and 2025.x prior to 2025.1.2.
Exploitation of this vulnerability allows for session hijacking, where an attacker can impersonate a user by stealing their authentication cookie.
Users are advised to update to OTRS version 2025.2.x. Note that there will be no patches for OTRS 7.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.