CVE-2025-52204

A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerInterface parameter
Configurations

No configuration.

History

26 Mar 2026, 16:16

Type Values Removed Values Added
References
  • () https://www.znuny.org/en/releases/znuny-7-3-1 -

24 Mar 2026, 16:16

Type Values Removed Values Added
CWE CWE-79
References () https://github.com/j0qq3r/CVE-2025-52204 - () https://github.com/j0qq3r/CVE-2025-52204 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) existe en Znuny::ITSM 6.5.x en el endpoint customer.pl a través del parámetro OTRSCustomerInterface

23 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 20:16

Updated : 2026-04-27 19:18


NVD link : CVE-2025-52204

Mitre link : CVE-2025-52204

CVE.ORG link : CVE-2025-52204


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')