Sceawere

Vulnerability Detail

CVE-2026-77506UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Znuny AgentTicketEmailResend Template XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.8
Creation Date
3h ago
Vendor
Znuny
Product
Znuny
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.8",
  "pubDate": "2026-08-20T21:17:10.673Z",
  "pubdate": "2026-08-20T21:17:10.673Z",
  "executiveSummary": "An input validation and output encoding vulnerability exists within the Znuny ticketing system, specifically affecting the AgentTicketEmailResend template.\nThe flaw manifests as a Cross-Site Scripting (XSS) vulnerability, allowing authenticated actors with specific agent privileges to inject arbitrary web scripts or HTML into the application context.\nThe affected product is Znuny in versions prior to LTS 6.5.22.\nSuccessful exploitation of this vulnerability can lead to the execution of malicious scripts in the browser of another user viewing the affected template, potentially resulting in session hijacking, unauthorized access to sensitive ticket data, or further interaction with the underlying application interface on behalf of the victim.\nThe risk implications include compromise of agent session integrity and unauthorized actions performed within the ticketing workflow.\nExploitation requires authenticated agent access to the Znuny system and the ability to interact with the AgentTicketEmailResend functionality, where malicious payloads can be supplied and subsequently rendered unsanitized by the client browser.",
  "technicalDetails": "The vulnerability resides in the template rendering engine or handling of parameters associated with the AgentTicketEmailResend component within Znuny prior to LTS 6.5.22.\nThe root cause is insufficient output encoding and lack of strict input sanitization of user-supplied or context-dependent data before it is reflected back into the Hypertext Markup Language (HTML) response generated by the AgentTicketEmailResend template.\nWhen an agent interacts with the email resend functionality, specially crafted payloads containing malicious JavaScript or HTML tags can be introduced into fields processed by the template.\nBecause the application fails to properly neutralize executable script content via context-aware output encoding, the browser interprets the injected payload as legitimate application code.\nThe attack flow typically proceeds with an authenticated agent supplying the malicious payload into a vulnerable parameter or field processed by the AgentTicketEmailResend interface.\nUpon submission and subsequent rendering of the template—either by the same agent or a secondary victim reviewing the email resend interface—the embedded script executes within the security context of the victim's active session.\nThis execution enables access to Document Object Model (DOM) elements, session tokens, and cookies accessible via scripting interfaces.\nThe vulnerable component is the AgentTicketEmailResend template and its associated backend rendering logic.\nAffected versions comprise all Znuny installations prior to LTS 6.5.22.\nAuthentication is required in the form of valid agent credentials, and the attack vector is exploitable over the network via standard HTTP/HTTPS protocols utilized by the web interface."
}
CVE-2026-77506: Znuny AgentTicketEmailResend Template XSS (MEDIUM Severity, CVSS: 4.8) - Sceawere