A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.
This issue affects:
The SameSite attribute for sensitive cookies is not set, or an insecure value is used.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Otrs | Otrs | 7.0.0 (including) | 2025.1.2 (including) |