The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/rapid7/metasploit-framework/pull/13828 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: rapid7
Published: 2020-08-06T15:45:28.912800Z
Updated: 2024-09-16T22:01:33.434Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7361
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-08-06T16:15:13.750
Modified: 2024-11-21T05:37:06.970
Link: CVE-2020-7361
Redhat
No data.