Impact
Znuny before LTS 6.5.22 is vulnerable to client‑side XSS when processing the AgentTicketEmailResend template. An attacker who can influence the content of that template can inject malicious scripts that execute in the browsers of users who view affected emails or ticket pages. The flaw is a classic stored XSS reflected through the template rendering engine, giving an attacker the ability to compromise user sessions or deface content.
Affected Systems
The vulnerability affects the Znuny ticketing system released by Znuny. Deployments running any version of Znuny prior to LTS 6.5.22 are susceptible. It impacts the core application that handles ticket emails and associated templates on all platforms where AgentTicketEmailResend is enabled.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate risk level. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting that no active exploits have been reported. Nevertheless, an attacker could embed malicious JavaScript in ticket content that is processed by the template, which would then run in the context of any user who opens the affected email or ticket. The most likely attack vector is through a crafted ticket or email that includes script tags, making the issue a potential threat in environments with many users or public ticket visibility.
OpenCVE Enrichment