Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2022-37700

Disclosure Date: September 19, 2022 (last updated February 24, 2025)
Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.
Attacker Value
Unknown

CVE-2021-27558

Disclosure Date: August 31, 2021 (last updated February 23, 2025)
A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such as data-link-creator.
Attacker Value
Unknown

CVE-2021-27557

Disclosure Date: August 31, 2021 (last updated February 23, 2025)
A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job.
Attacker Value
Unknown

CVE-2021-27556

Disclosure Date: August 31, 2021 (last updated February 23, 2025)
The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to System.
Attacker Value
Unknown

CVE-2020-28165

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.
Attacker Value
Unknown

CVE-2020-7361

Disclosure Date: July 08, 2020 (last updated February 21, 2025)
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.