PT-2025-15072 · Zammad · Zammad

·

CVE-2025-32359

·

Published

2025-04-05

·

Updated

2025-04-15

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zammad versions 6.4.0 through 6.4.1
Description The issue concerns client-side enforcement of server-side security in Zammad. Specifically, when users change their two-factor authentication configuration, they are required to re-authenticate with their current password first. However, this security measure is only enforced at the front-end level and not when the API is used directly.
Recommendations For Zammad versions 6.4.0 through 6.4.1, update to version 6.4.2 to resolve the issue. As a temporary workaround, consider restricting direct API access for users until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32359

Affected Products

Zammad