CVE-2025-32358
05.04.2025, 21:15
In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in Zammad, which are triggered as POST requests when certain conditions are met. If a webhook endpoint returned a redirect response, Zammad would follow it automatically with another GET request. This could be abused by an attacker to cause GET requests for example in the local network.
Vendor | Product | Version |
---|---|---|
zammad | zammad | 6.4.0 ≤ 𝑥 < 6.4.2 |
𝑥
= Vulnerable software versions