A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 is sufficient to fix this issue. You should upgrade the affected component.
History

Thu, 04 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Zentao
Zentao zentao
CPEs cpe:2.3:a:zentao:zentao:*:*:*:*:*:*:*:*
Vendors & Products Zentao
Zentao zentao

Mon, 01 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Easycorp
Easycorp zentao
Vendors & Products Easycorp
Easycorp zentao

Mon, 01 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 30 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 is sufficient to fix this issue. You should upgrade the affected component.
Title ZenTao File control.php delete privileges management
Weaknesses CWE-266
CWE-269
References
Metrics cvssV2_0

{'score': 5.5, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-11-30T10:32:08.651Z

Updated: 2025-12-01T15:03:55.578Z

Reserved: 2025-11-29T20:21:18.012Z

Link: CVE-2025-13787

cve-icon Vulnrichment

Updated: 2025-12-01T15:03:28.743Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-30T11:15:48.567

Modified: 2025-12-04T16:44:07.470

Link: CVE-2025-13787

cve-icon Redhat

No data.