Server-Side Request Forgery in Zammad by Zammad
CVE-2025-32358
4.1MEDIUM
What is CVE-2025-32358?
In Zammad versions 6.4.x prior to 6.4.2, an SSRF vulnerability exists that allows authenticated admin users to inadvertently expose local network services. This vulnerability is triggered through the use of webhooks, which upon receiving a redirect response will issue an automatic GET request to the redirected endpoint. An attacker could exploit this behavior to manipulate webhook configurations, leading to unauthorized access to internal resources and potential data exposure.
Affected Version(s)
Zammad 6.4 < 6.4.2
