Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2022-37700
Disclosure Date: September 19, 2022 (last updated February 24, 2025)
Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.
0
Attacker Value
Unknown
CVE-2021-27558
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such as data-link-creator.
0
Attacker Value
Unknown
CVE-2021-27557
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job.
0
Attacker Value
Unknown
CVE-2021-27556
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to System.
0
Attacker Value
Unknown
CVE-2020-28165
Disclosure Date: August 12, 2021 (last updated February 23, 2025)
The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.
0
Attacker Value
Unknown
CVE-2020-7361
Disclosure Date: July 08, 2020 (last updated February 21, 2025)
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.
0
Attacker Value
Unknown
CVE-2019-14731
Disclosure Date: August 07, 2019 (last updated November 27, 2024)
An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.
0