Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed.Referenceshttps://www.znuny.comhttps://www.znuny.org/en/advisories/zsa-2024-05https://www.znuny.org/en/advisories