VendorsEasycorpzentao12.5.3
Vulnerabilities

Easycorp Zentao 12.5.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2021-27556
The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to System.
Published 2021-08-31 · Modified
9.0EPSS 0.040
CVE-2021-27558
A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such as data-link-creator.
Published 2021-08-31 · Modified
6.1EPSS 0.008
CVE-2021-27557
A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job.
Published 2021-08-31 · Modified
4.3EPSS 0.004