ZenTao Biz version 4.1.3 and before is vulnerable to Cross Site Request Forgery (CSRF).
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
ZenTao Enterprise Edition version 4.1.3 and before is vulnerable to Cross Site Scripting (XSS).
ZenTao Biz version 4.1.3 and before has a Cross Site Scripting (XSS) vulnerability in the Version Library.