CVE-2025-26845

An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*
cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*
cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:*

History

16 May 2025, 15:39

Type Values Removed Values Added
CWE CWE-94
CPE cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*
cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:*
First Time Znuny znuny
Znuny
References () https://www.znuny.com - () https://www.znuny.com - Product
References () https://www.znuny.org/en/advisories/zsa-2025-03 - () https://www.znuny.org/en/advisories/zsa-2025-03 - Vendor Advisory

12 May 2025, 17:32

Type Values Removed Values Added
Summary
  • (es) Se detectó un problema de inyección de evaluación en Znuny hasta la versión 7.1.3. Un usuario con acceso de escritura al archivo de configuración puede usarlo para ejecutar un comando ejecutado por el usuario que ejecuta el script backup.pl.

08 May 2025, 19:16

Type Values Removed Values Added
CWE CWE-95
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

08 May 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-08 17:16

Updated : 2025-05-16 15:39


NVD link : CVE-2025-26845

Mitre link : CVE-2025-26845

CVE.ORG link : CVE-2025-26845


JSON object : View

Products Affected

znuny

  • znuny
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')