PT-2025-15072 · Zammad · Zammad
Rodrigo Magalhães
+1
·
Published
2025-04-05
·
Updated
2025-04-15
·
CVE-2025-32359
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zammad versions 6.4.0 through 6.4.1
Description
The issue concerns client-side enforcement of server-side security in Zammad. Specifically, when users change their two-factor authentication configuration, they are required to re-authenticate with their current password first. However, this security measure is only enforced at the front-end level and not when the API is used directly.
Recommendations
For Zammad versions 6.4.0 through 6.4.1, update to version 6.4.2 to resolve the issue.
As a temporary workaround, consider restricting direct API access for users until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zammad