VYPR
Unrated severityNVD Advisory· Published Apr 5, 2025· Updated Apr 7, 2025

CVE-2025-32357

CVE-2025-32357

Description

In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.