Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed.
History

Thu, 17 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Znuny
Znuny znuny
Weaknesses CWE-79
CPEs cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:*
cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*
Vendors & Products Znuny
Znuny znuny
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 15 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Oct 2024 21:00:00 +0000

Type Values Removed Values Added
Description Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-11T00:00:00

Updated: 2024-10-15T15:39:23.426Z

Reserved: 2024-10-09T00:00:00

Link: CVE-2024-48937

cve-icon Vulnrichment

Updated: 2024-10-15T15:39:17.921Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-11T21:15:07.307

Modified: 2024-10-17T19:48:11.163

Link: CVE-2024-48937

cve-icon Redhat

No data.