CVE-2025-24387 | OTRS up to 7.0.x/8.0.x/2023.x/2024.x/2025.1.2 Endpoint sensitive cookie with improper samesite attribute
A vulnerability was found in OTRS up to 7.0.x/8.0.x/2023.x/2024.x/2025.1.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Endpoint. The manipulation leads to sensitive cookie with improper samesite attribute.
This vulnerability is handled as CVE-2025-24387. The attack may be launched remotely. There is no exploit available.