ZenTao Pro Command Injection
CVE-2020-7361

9.6CRITICAL

Key Information:

Vendor

Easycorp

Vendor
CVE Published:
6 August 2020

What is CVE-2020-7361?

The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.

Affected Version(s)

ZenTao Pro 8.8.2

References

EPSS Score

17% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Daniel MonzĂłn.
.