Vulnerabilities > Easycorp > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-44827 Command Injection vulnerability in Easycorp Zentao, Zentao BIZ and Zentao MAX
An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function.
network
low complexity
easycorp CWE-77
8.8
2023-01-19 CVE-2022-47745 SQL Injection vulnerability in Easycorp Zentao
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection.
network
low complexity
easycorp CWE-89
8.8
2022-09-19 CVE-2022-37700 Path Traversal vulnerability in Easycorp Zentao 15.0
Zentao Demo15 is vulnerable to Directory Traversal.
network
low complexity
easycorp CWE-22
7.5
2021-08-31 CVE-2021-27556 OS Command Injection vulnerability in Easycorp Zentao 12.5.3
The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to System.
network
low complexity
easycorp CWE-78
7.2
2020-08-06 CVE-2020-7361 OS Command Injection vulnerability in Easycorp Zentao PRO 8.8.2
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component.
network
low complexity
easycorp CWE-78
8.8