Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-32359

Опубликовано: 05 апр. 2025
Источник: nvd
CVSS3: 4.8
CVSS3: 8.8
EPSS Низкий

Описание

In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end level, and not when using the API directly.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:*
Версия от 6.4.0 (включая) до 6.4.2 (исключая)

EPSS

Процентиль: 32%
0.00123
Низкий

4.8 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-602
NVD-CWE-Other

Связанные уязвимости

CVSS3: 4.8
debian
10 месяцев назад

In Zammad 6.4.x before 6.4.2, there is client-side enforcement of serv ...

CVSS3: 4.8
github
10 месяцев назад

In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end level, and not when using the API directly.

EPSS

Процентиль: 32%
0.00123
Низкий

4.8 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-602
NVD-CWE-Other