ZSA-2026-13
A SQL injection vulnerability exists in the agent login (Kernel::System::Auth::DB). The submitted username was inserted into the login SQL query after being escaped with the database's Quote() method instead of being passed as a bound parameter, which could allow an attacker to manipulate the query used to authenticate agent logins.
Fixed in: Znuny LTS 6.5.25 and Znuny 7.3.7