Vulnerabilities > Easycorp

DATE CVE VULNERABILITY TITLE RISK
2021-08-31 CVE-2021-27557 Cross-Site Request Forgery (CSRF) vulnerability in Easycorp Zentao 12.5.3
A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job.
network
easycorp CWE-352
4.3
2021-08-31 CVE-2021-27558 Cross-site Scripting vulnerability in Easycorp Zentao 12.5.3
A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such as data-link-creator.
network
easycorp CWE-79
4.3
2020-08-06 CVE-2020-7361 OS Command Injection vulnerability in Easycorp Zentao PRO 8.8.2
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component.
network
low complexity
easycorp CWE-78
critical
9.0