An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateAJAX subaction can be used to set user preferences with arbitrary keys. When fetching user data via GetUserData, these keys and values are retrieved and given as a whole to other function calls, which then might use these keys/values to affect permissions or other settings.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.znuny.org/en/advisories/zsa-2025-07 |
![]() ![]() |
https://znuny.com |
![]() ![]() |
History
Thu, 12 Jun 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Znuny
Znuny znuny |
|
CPEs | cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:* | |
Vendors & Products |
Znuny
Znuny znuny |
Mon, 12 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Thu, 08 May 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateAJAX subaction can be used to set user preferences with arbitrary keys. When fetching user data via GetUserData, these keys and values are retrieved and given as a whole to other function calls, which then might use these keys/values to affect permissions or other settings. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-05-08T00:00:00.000Z
Updated: 2025-05-12T18:31:16.725Z
Reserved: 2025-04-19T00:00:00.000Z
Link: CVE-2025-43926

Updated: 2025-05-12T18:30:52.505Z

Status : Analyzed
Published: 2025-05-08T16:15:26.317
Modified: 2025-06-12T16:44:04.490
Link: CVE-2025-43926

No data.