CVE-2024-48938

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/10/2024
Last modified:
14/03/2025

Description

Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to high CPU usage and block the parsing process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:* 6.0.0 (including) 6.1.0 (excluding)
cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:* 6.5.1 (including) 6.5.10 (including)
cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:* 7.0.1 (including) 7.0.16 (including)