CVE-2024-24202

An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:easycorp:zentao:18.10:*:*:*:community:*:*:*
cpe:2.3:a:easycorp:zentao_biz:8.10:*:*:*:*:*:*:*
cpe:2.3:a:easycorp:zentao_max:4.10:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-08 05:15

Updated : 2024-02-15 15:24


NVD link : CVE-2024-24202

Mitre link : CVE-2024-24202

CVE.ORG link : CVE-2024-24202


JSON object : View

Products Affected

easycorp

  • zentao_biz
  • zentao
  • zentao_max
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type