Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed.
| Software | From | Fixed in |
|---|---|---|
| znuny / znuny | 6.0.0 | 6.1.0 |
| znuny / znuny | 7.0.1 | 7.0.16.x |
| znuny / znuny | 6.5.1 | 6.5.10.x |