PT-2025-15072 · Zammad · Zammad

Rodrigo Magalhães

+1

·

Published

2025-04-05

·

Updated

2025-04-15

·

CVE-2025-32359

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zammad versions 6.4.0 through 6.4.1
Description The issue concerns client-side enforcement of server-side security in Zammad. Specifically, when users change their two-factor authentication configuration, they are required to re-authenticate with their current password first. However, this security measure is only enforced at the front-end level and not when the API is used directly.
Recommendations For Zammad versions 6.4.0 through 6.4.1, update to version 6.4.2 to resolve the issue. As a temporary workaround, consider restricting direct API access for users until the update is applied.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-32359

Affected Products

Zammad