A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 is sufficient to fix this issue. You should upgrade the affected component.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 05 Dec 2025 01:45:00 +0900

Type Values Removed Values Added
First Time appeared Zentao
Zentao zentao
CPEs cpe:2.3:a:zentao:zentao:*:*:*:*:*:*:*:*
Vendors & Products Zentao
Zentao zentao

Tue, 02 Dec 2025 00:30:00 +0900

Type Values Removed Values Added
First Time appeared Easycorp
Easycorp zentao
Vendors & Products Easycorp
Easycorp zentao

Tue, 02 Dec 2025 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 30 Nov 2025 19:45:00 +0900

Type Values Removed Values Added
Description A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 is sufficient to fix this issue. You should upgrade the affected component.
Title ZenTao File control.php delete privileges management
Weaknesses CWE-266
CWE-269
References
Metrics cvssV2_0

{'score': 5.5, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-12-01T15:03:55.578Z

Reserved: 2025-11-29T20:21:18.012Z

Link: CVE-2025-13787

cve-icon Vulnrichment

Updated: 2025-12-01T15:03:28.743Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-30T11:15:48.567

Modified: 2025-12-04T16:44:07.470

Link: CVE-2025-13787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-02T00:18:04Z

Weaknesses