An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 02 Sep 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Znuny
Znuny znuny
CPEs cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:*
cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*
Vendors & Products Znuny
Znuny znuny

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T02:13:39.406Z

Reserved: 2024-04-15T00:00:00

Link: CVE-2024-32493

cve-icon Vulnrichment

Updated: 2024-08-02T02:13:39.406Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-29T17:15:19.300

Modified: 2025-09-02T21:19:37.193

Link: CVE-2024-32493

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.