CVE-2024-24202
EUVD-2024-2162608.02.2024, 05:15
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| easycorp | zentao | 18.10 |
| easycorp | zentao_biz | 8.10 |
| easycorp | zentao_max | 4.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration