HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2025-24387
发布日期2025-03-10T09:28:31.053Z
更新日期2025-03-10T13:12:40.237Z
状态PUBLISHED
受影响的供应商OTRS AG
受影响的产品OTRS
描述A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.   This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.x

参考链接:

Image Additional Image