The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4949-1 | jetty9 security update |
EUVD |
EUVD-2020-20651 | The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.zentao.net/dynamic/zentaopms12.4.2-80263.html |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:33:57.779Z
Reserved: 2020-11-02T00:00:00.000Z
Link: CVE-2020-28165
No data.
Status : Modified
Published: 2021-08-12T12:15:07.127
Modified: 2024-11-21T05:22:25.437
Link: CVE-2020-28165
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD