CVE-2025-26845

An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*
cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*
cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:*

History

16 May 2025, 15:39

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-08 17:16

Updated : 2025-05-16 15:39


NVD link : CVE-2025-26845

Mitre link : CVE-2025-26845

CVE.ORG link : CVE-2025-26845


JSON object : View

Products Affected

znuny

  • znuny
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')