Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed.
{ "binaries": [ { "binary_name": "otrs2", "binary_version": "6.5.14-1" }, { "binary_name": "znuny", "binary_version": "6.5.14-1" } ], "availability": "No subscription required" }