Vulnerabilities > CVE-2025-32359 - Unspecified vulnerability in Zammad 6.4.0/6.4.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end level, and not when using the API directly.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |