Home
MEDIUM: 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NDefault status
unknown
Any version before 6.5.21
affected
7.0.0 (semver) before 7.3.3
affected
Description
In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 6.5.21
7.0.0 (semver) before 7.3.3
References
www.znuny.org/en/advisories/zsa-2026-10