Server-Side Request Forgery in Zammad by Zammad
CVE-2025-32358

4.1MEDIUM

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
5 April 2025

What is CVE-2025-32358?

In Zammad versions 6.4.x prior to 6.4.2, an SSRF vulnerability exists that allows authenticated admin users to inadvertently expose local network services. This vulnerability is triggered through the use of webhooks, which upon receiving a redirect response will issue an automatic GET request to the redirected endpoint. An attacker could exploit this behavior to manipulate webhook configurations, leading to unauthorized access to internal resources and potential data exposure.

Affected Version(s)

Zammad 6.4 < 6.4.2

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.