CVE-2020-7361: ZenTao Pro Command Injection
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7361?
CVE-2020-7361 is a OS command injection vulnerability in the EasyCorp ZenTao Pro application.
How does CVE-2020-7361 affect EasyCorp ZenTao Pro?
CVE-2020-7361 allows attackers to construct and send arbitrary OS commands via the 'path' parameter, which will run with elevated privileges.
What is the severity of CVE-2020-7361?
CVE-2020-7361 has a severity level of 8.8, which is considered critical.
How can I fix CVE-2020-7361 in EasyCorp ZenTao Pro?
Currently, there is no official fix available for CVE-2020-7361. It is recommended to implement a web application firewall (WAF) and monitor for any suspicious activity.
Where can I find more information about CVE-2020-7361?
You can find more information about CVE-2020-7361 on the GitHub page for the Metasploit Framework pull request with ID 13828.