The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
easycorp zentao |