Metrics
Affected Vendors & Products
Thu, 04 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zentao
Zentao zentao |
|
| CPEs | cpe:2.3:a:zentao:zentao:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zentao
Zentao zentao |
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Easycorp
Easycorp zentao |
|
| Vendors & Products |
Easycorp
Easycorp zentao |
Mon, 01 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 30 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 is sufficient to fix this issue. You should upgrade the affected component. | |
| Title | ZenTao File control.php delete privileges management | |
| Weaknesses | CWE-266 CWE-269 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-11-30T10:32:08.651Z
Updated: 2025-12-01T15:03:55.578Z
Reserved: 2025-11-29T20:21:18.012Z
Link: CVE-2025-13787
Updated: 2025-12-01T15:03:28.743Z
Status : Analyzed
Published: 2025-11-30T11:15:48.567
Modified: 2025-12-04T16:44:07.470
Link: CVE-2025-13787
No data.