In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer was able to see details about shared drafts for their customer tickets in the browser console, which may contain confidential information, and also to manipulate them via API.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://zammad.com/en/advisories/zaa-2025-03 |
![]() ![]() |
History
Tue, 15 Apr 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zammad
Zammad zammad |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:a:zammad:zammad:*:*:*:*:*:*:*:* | |
Vendors & Products |
Zammad
Zammad zammad |
Mon, 07 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 05 Apr 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-402 | |
Metrics |
cvssV3_1
|
Sat, 05 Apr 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer was able to see details about shared drafts for their customer tickets in the browser console, which may contain confidential information, and also to manipulate them via API. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-07T16:12:08.839Z
Reserved: 2025-04-05T00:00:00.000Z
Link: CVE-2025-32360

Updated: 2025-04-07T16:12:05.545Z

Status : Analyzed
Published: 2025-04-05T21:15:40.820
Modified: 2025-04-15T15:25:12.600
Link: CVE-2025-32360

No data.