CVE-2025-24388 Information

Description

A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user.

This issue affects:

OTRS 7.0.X

OTRS 8.0.X
OTRS 2023.X
OTRS 2024.X
OTRS 2025.X

((OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

Reference

https://otrs.com/release-notes/otrs-security-advisory-2025-06/

CNNVD-202506-1885 (Published: 2025-06-16)

Share on: