Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6wcp-gj2x-5f4w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.

The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.

EPSS

Процентиль: 97%
0.35969
Средний

Связанные уязвимости

CVSS3: 9.6
nvd
больше 5 лет назад

The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.

EPSS

Процентиль: 97%
0.35969
Средний