CVE-2025-24388: Otrs AG Otrs
Low severity, CVSS 3.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected
Affected products
- Otrs AG Otrs: from 7.0, before 7.1 (fixed in 7.1); from 8.0, before 8.1 (fixed in 8.1); from 2023, before 2024 (fixed in 2024); from 2024, before 2025 (fixed in 2025); from 2025, up to and including 2025.5.1
- Otrs AG Otrs Community Edition: from 6.0, before 6.1 (fixed in 6.1)
Published 2025-06-16. Last modified 2026-06-17.