← back
CVE-2020-7361criticalCWE-78

ZenTao Pro Command Injection

48Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 9.6epss 17%
from disclosure to weapon0 days
Published on NVDAug 6
metasploitJun 20
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected products
EasyCorp · ZenTao Pro