CVE-2025-32360: High severity zammad vulnerability
In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer was able to see details about shared drafts for their customer tickets in the browser console, which may contain confidential information, and also to manipulate them via API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32360?
CVE-2025-32360 is considered a medium severity vulnerability due to potential information exposure.
How do I fix CVE-2025-32360?
To fix CVE-2025-32360, upgrade Zammad to version 6.4.2 or later.
What does CVE-2025-32360 expose?
CVE-2025-32360 exposes shared article draft details to logged-in customers, which may contain confidential information.
Who is affected by CVE-2025-32360?
Zammad users running versions before 6.4.2 are affected by CVE-2025-32360.
Is CVE-2025-32360 commonly exploited?
There is currently no evidence suggesting that CVE-2025-32360 is commonly exploited in the wild.