CVE-2022-47745: SQL Injection
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-47745?
CVE-2022-47745 refers to a vulnerability in ZenTao versions 16.4 to 18.0.beta1 that allows for SQL injection.
How can the SQL injection vulnerability in ZenTao be exploited?
The SQL injection vulnerability in ZenTao can be exploited by constructing a special request and sending it to the importNotice function after logging in with any user.
What is the severity of CVE-2022-47745?
CVE-2022-47745 has a severity rating of 8.8 (high).
How can I mitigate the SQL injection vulnerability in ZenTao?
To mitigate the SQL injection vulnerability in ZenTao, it is recommended to upgrade to a version beyond 18.0.beta1 or apply the necessary patches provided by EasyCorp ZenTao.
Are there any references available for CVE-2022-47745?
Yes, you can find references for CVE-2022-47745 at the following URLs: [GitHub Issue 106](https://github.com/easysoft/zentaopms/issues/106) and [GitHub l3s10n](https://github.com/l3s10n/ZenTaoPMS_SqlInjection).