CVE-2024-48937

NameCVE-2024-48937
DescriptionZnuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
znuny (PTS)bookworm/non-free6.5.1-1vulnerable
sid/non-free, trixie/non-free6.5.11-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
znunysource(unstable)6.5.11-1

Notes

[bookworm] - znuny <no-dsa> (Non-free not supported)
https://www.znuny.org/en/advisories/zsa-2024-05

Search for package or bug name: Reporting problems