Vulnerabilities > Easycorp > Zentao > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-08 CVE-2024-24216 Command Injection vulnerability in Easycorp Zentao
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.
network
low complexity
easycorp CWE-77
critical
9.8
2024-02-08 CVE-2024-24202 Unrestricted Upload of File with Dangerous Type vulnerability in Easycorp Zentao, Zentao BIZ and Zentao MAX
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.
network
low complexity
easycorp CWE-434
critical
9.8
2021-08-31 CVE-2021-27556 OS Command Injection vulnerability in Easycorp Zentao 12.5.3
The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to System.
network
low complexity
easycorp CWE-78
critical
9.0