CVE-2024-24202
08.02.2024, 05:15
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.Enginsight
Vendor | Product | Version |
---|---|---|
easycorp | zentao | 18.10 |
easycorp | zentao_biz | 8.10 |
easycorp | zentao_max | 4.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration