An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.
[ { "events": [ { "introduced": "6.5.1" }, { "last_affected": "6.5.7" } ] }, { "events": [ { "introduced": "7.0.1" }, { "last_affected": "7.0.16" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-32493.json"