CVE-2024-48937

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/10/2024
Last modified:
13/03/2025

Description

Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:* 6.0.0 (including) 6.1.0 (excluding)
cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:* 6.5.1 (including) 6.5.10 (including)
cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:* 7.0.1 (including) 7.0.16 (including)