PT-2026-27200 · Unknown · Znuny::Itsm

Published

2026-03-23

·

Updated

2026-04-28

·

CVE-2025-52204

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Znuny::ITSM versions 6.5.x
Description A Cross-Site Scripting (XSS) issue exists in Znuny::ITSM 6.5.x. The issue is located in the customer.pl API endpoint and is triggered through the OTRSCustomerInterface parameter. This allows for potential malicious script injection.
Recommendations Address the issue in the customer.pl endpoint by sanitizing the OTRSCustomerInterface parameter.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-52204

Affected Products

Znuny::Itsm