Executive brief
Znuny, an open-source ticket request system, contains a security vulnerability in its communication log administration interface. An attacker can trick an administrator into clicking a malicious link, allowing the attacker to run unauthorized scripts in the administrator's browser. This could lead to the theft of session information or the performance of unauthorized actions within the ticketing system.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the AdminCommunicationLog (communication log administration view) of Znuny. The root cause is the failure to properly escape URL parameters before rendering them into the page output. An attacker can exploit this by crafting a malicious URL containing JavaScript payloads. When an authenticated administrator visits this URL, the script executes within their browser session. This vulnerability is tracked as CVE-2026-50592 and is fixed in Znuny LTS 6.5.21 and Znuny 7.3.3.
Affected products
- Znuny Znuny LTS 6.0, 6.1, 6.2, 6.3, 6.4, 6.5.1 through 6.5.20
- Znuny Znuny 7.0, 7.1, 7.2, 7.3.1 through 7.3.2
Timeline
- 2026-05-27: advisory: Vendor advisory ZSA-2026-10 released
- 2026-06-05: disclosed: CVE published to NVD