CVE-2024-24216: Command Injection
Published Feb 8, 2024
·Updated
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.
Affected Software
1 affected component
EasyCorp ZenTao>=18.0<=18.10
Event History
Feb 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24216?
CVE-2024-24216 has a high severity level due to its potential for remote code execution.
2
How do I fix CVE-2024-24216?
To fix CVE-2024-24216, update ZenTao to version 18.11 or later.
3
Which versions of ZenTao are affected by CVE-2024-24216?
CVE-2024-24216 affects ZenTao versions from 18.0 to 18.10.
4
What type of vulnerability is CVE-2024-24216?
CVE-2024-24216 is a remote code execution (RCE) vulnerability.
5
How can I determine if my ZenTao installation is vulnerable to CVE-2024-24216?
You can determine if your installation is vulnerable by checking if it is running ZenTao version between 18.0 and 18.10.