CVE-2024-48938
- EPSS 0.59%
- Veröffentlicht 11.10.2024 21:15:07
- Zuletzt bearbeitet 14.03.2025 14:15:16
Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to high CPU usage and block the parsing process.
CVE-2024-32491
- EPSS 0.72%
- Veröffentlicht 29.04.2024 17:15:19
- Zuletzt bearbeitet 02.09.2025 21:21:38
An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a manipulated AJAX Request) to an arbitrary writable location by traversing paths. Arbitrary code can be ...
CVE-2024-32492
- EPSS 0.53%
- Veröffentlicht 29.04.2024 17:15:19
- Zuletzt bearbeitet 02.09.2025 21:19:51
An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JavaScript.
CVE-2024-32493
- EPSS 0.71%
- Veröffentlicht 29.04.2024 17:15:19
- Zuletzt bearbeitet 02.09.2025 21:19:37
An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.