CVE-2025-26845

An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:*
cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*
cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*

History

16 May 2025, 15:39

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Znuny
Znuny znuny
CWE CWE-94
References () https://www.znuny.com - () https://www.znuny.com - Product
References () https://www.znuny.org/en/advisories/zsa-2025-03 - () https://www.znuny.org/en/advisories/zsa-2025-03 - Vendor Advisory
CPE cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*
cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:*

08 May 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-08 17:16

Updated : 2025-05-16 15:39


NVD link : CVE-2025-26845

Mitre link : CVE-2025-26845


JSON object : View

Products Affected

znuny

  • znuny
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')