Vulnerabilities > Easycorp
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-31 | CVE-2021-27556 | OS Command Injection vulnerability in Easycorp Zentao 12.5.3 The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to System. | 9.0 |
2021-08-31 | CVE-2021-27557 | Cross-Site Request Forgery (CSRF) vulnerability in Easycorp Zentao 12.5.3 A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job. | 4.3 |
2021-08-31 | CVE-2021-27558 | Cross-site Scripting vulnerability in Easycorp Zentao 12.5.3 A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such as data-link-creator. | 4.3 |
2020-08-06 | CVE-2020-7361 | OS Command Injection vulnerability in Easycorp Zentao PRO 8.8.2 The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. | 9.0 |