Vulnerabilities > Easycorp

DATE CVE VULNERABILITY TITLE RISK
2022-09-19 CVE-2022-37700 Path Traversal vulnerability in Easycorp Zentao 15.0
Zentao Demo15 is vulnerable to Directory Traversal.
network
low complexity
easycorp CWE-22
7.5
2021-08-31 CVE-2021-27556 OS Command Injection vulnerability in Easycorp Zentao 12.5.3
The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to System.
network
low complexity
easycorp CWE-78
7.2
2021-08-31 CVE-2021-27557 Cross-Site Request Forgery (CSRF) vulnerability in Easycorp Zentao 12.5.3
A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job.
network
low complexity
easycorp CWE-352
4.3
2021-08-31 CVE-2021-27558 Cross-site Scripting vulnerability in Easycorp Zentao 12.5.3
A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such as data-link-creator.
network
low complexity
easycorp CWE-79
6.1
2021-08-12 CVE-2020-28165 Unrestricted Upload of File with Dangerous Type vulnerability in Easycorp Zentao
The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability.
network
low complexity
easycorp CWE-434
critical
9.8
2020-08-06 CVE-2020-7361 OS Command Injection vulnerability in Easycorp Zentao PRO 8.8.2
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component.
network
low complexity
easycorp CWE-78
8.8