CVE-2025-32359
05.04.2025, 21:15
In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end level, and not when using the API directly.Enginsight
Vendor | Product | Version |
---|---|---|
zammad | zammad | 6.4.0 ≤ 𝑥 < 6.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration