First published: Tue Oct 10 2023(Updated: )
An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EasyCorp ZenTao | <=18.6 | |
Easycorp Zentao Biz | <=8.6 | |
Easycorp Zentao Max | <=4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44827 is a vulnerability that allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function in ZenTao Community Edition, ZenTao Biz, and ZenTao Max.
The severity of CVE-2023-44827 is high, with a CVSS score of 8.8.
ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, and ZenTao Max v.4.7 and before are affected by CVE-2023-44827.
An attacker can exploit CVE-2023-44827 by executing a crafted script to the Office Conversion Settings function in ZenTao.
At the moment, there is no known fix for CVE-2023-44827. It is recommended to update to the latest version of ZenTao when a fix becomes available.