Znuny
cpe:2.3:a:znuny:znuny:*:*:*:*:*:*:*
- >= 6.0, <= 6.5.14
- >= 7.0, <= 7.1.6
A vulnerability exists in Znuny versions through 6.5.14 and 7.x through 7.1.6, allowing arbitrary user preferences to be set via custom AJAX calls to the AgentPreferences UpdateAJAX subaction. The injected keys and values are retrieved in their entirety when user data is fetched through GetUserData. This data can then be passed to other function calls, potentially impacting permissions or other settings.
Exploitation of this vulnerability could lead to unauthorized modification of user preferences, which may be used to manipulate permissions or other settings within the application.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.