Vulnerabilities (CVE)

Filtered by vendor Easycorp Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6439 1 Easycorp 1 Zentao 2023-12-06 N/A 6.1 MEDIUM
A vulnerability classified as problematic was found in ZenTao PMS 18.8. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246439.
CVE-2023-46475 1 Easycorp 1 Zentao 2023-11-09 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.
CVE-2021-27557 1 Easycorp 1 Zentao 2021-09-08 4.3 MEDIUM 4.3 MEDIUM
A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job.
CVE-2021-27558 1 Easycorp 1 Zentao 2021-09-08 4.3 MEDIUM 6.1 MEDIUM
A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such as data-link-creator.