VYPR
Unrated severityNVD Advisory· Published Oct 11, 2024· Updated Mar 13, 2025

CVE-2024-48937

CVE-2024-48937

Description

Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed.

Affected products

2
  • Znuny/Znunycpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: >= 6.5.1, <= 6.5.10 || >= 7.0.1, <= 7.0.16

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.