Executive brief
Znuny, a popular open-source help desk and ticketing system, is vulnerable to a security flaw in its customer portal. An attacker can send a specially crafted link to a user; if clicked, the attacker can run malicious scripts in the user's browser. This could lead to unauthorized actions being performed on the user's behalf, the theft of login information, or the display of deceptive content to trick customers.
Technical details
A reflected Cross-Site Scripting (XSS) and HTML injection vulnerability exists in Znuny's customer.pl endpoint. The vulnerability is rooted in the improper neutralization of input provided via the OTRSCustomerInterface parameter (or the parameter defined by CustomerPanelSessionName in the system configuration). An unauthenticated remote attacker can exploit this by tricking a user into clicking a crafted GET request, allowing the execution of arbitrary JavaScript or the injection of malicious HTML within the context of the victim's browser session. The issue affects both the 6.5.x LTS branch and the 7.x branch. The vendor has released patches in Znuny LTS 6.5.19 and Znuny 7.3.1.
Affected products
- Znuny Znuny LTS 6.5.9 - 6.5.18
- Znuny Znuny 7.0.11 - 7.2.3
Timeline
- 2026-03-23: disclosed
- 2026-03-25: patched: Znuny 7.3.1 and LTS 6.5.19 released