Remote Code Execution Vulnerability in EasyCorp ZenTao by Remote Admins
CVE-2021-27556

7.2HIGH

Key Information:

Vendor

Easycorp

Status
Vendor
CVE Published:
31 August 2021

What is CVE-2021-27556?

In EasyCorp ZenTao version 12.5.3, a vulnerability exists within the Cron job tab that enables remote attackers with administrator privileges to execute arbitrary code. By manipulating the 'type' parameter and setting it to 'System', these attackers can gain unauthorized control and perform malicious actions on the system. This highlights a significant security issue for installations running this version of ZenTao, requiring immediate attention and remediation.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.