← volver
CVE-2020-7361criticalCWE-78

ZenTao Pro Command Injection

48Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 9.6epss 17%
de la publicación al arma0 días
Publicada en NVD6 ago
metasploit20 jun
probabilidad de explotación
17%top 3% de las CVE
explotación observada
noninguna fuente lo reporta
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Productos afectados
EasyCorp · ZenTao Pro