CVE-2023-44827: Command Injection
An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-44827?
CVE-2023-44827 is a vulnerability that allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function in ZenTao Community Edition, ZenTao Biz, and ZenTao Max.
What is the severity of CVE-2023-44827?
The severity of CVE-2023-44827 is high, with a CVSS score of 8.8.
Which software is affected by CVE-2023-44827?
ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, and ZenTao Max v.4.7 and before are affected by CVE-2023-44827.
How can an attacker exploit CVE-2023-44827?
An attacker can exploit CVE-2023-44827 by executing a crafted script to the Office Conversion Settings function in ZenTao.
Is there a fix for CVE-2023-44827?
At the moment, there is no known fix for CVE-2023-44827. It is recommended to update to the latest version of ZenTao when a fix becomes available.