OTRS
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*
- ~7.0
- ~8.0
- ~2023
- ~2024
A session hijacking vulnerability exists in OTRS Application Server and reverse proxy settings, caused by missing attributes for sensitive cookie settings in HTTPS sessions. This issue affects OTRS versions 7.0.X, 8.0.X, 2023.X, and 2024.X.
Exploitation of this vulnerability allows for session hijacking, where an attacker can take over a user's session.
Users are advised to update to OTRS version 2025.1.x. Note that there will be no patches for OTRS 7.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.