Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-px5m-vp2j-j7xw

Опубликовано: 30 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 6.3

Описание

A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. Upgrading to version 21.7.6 mitigates this issue. It is suggested to upgrade the affected component.

A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. Upgrading to version 21.7.6 mitigates this issue. It is suggested to upgrade the affected component.

EPSS

Процентиль: 16%
0.00051
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.3
nvd
2 месяца назад

A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. Upgrading to version 21.7.6 mitigates this issue. It is suggested to upgrade the affected component.

EPSS

Процентиль: 16%
0.00051
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-918