Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-43926


An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateAJAX subaction can be used to set user preferences with arbitrary keys. When fetching user data via GetUserData, these keys and values are retrieved and given as a whole to other function calls, which then might use these keys/values to affect permissions or other settings.


Published

2025-05-08T16:15:26.317

Last Modified

2025-06-12T16:44:04.490

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application znuny znuny ≤ 6.5.14 Yes
Application znuny znuny ≤ 7.1.6 Yes

References