Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NDefault status
unknown
6.0.0 (semver) before 6.5.21
affected
7.0.0 (semver) before 7.3.3
affected
Description
In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
6.0.0 (semver) before 6.5.21
7.0.0 (semver) before 7.3.3
References
www.znuny.org/en/advisories/zsa-2026-11