CVE-2023-44827

HIGH

ZenTao < 18.6, ZenTao Biz < 8.6, ZenTao Max < 4.7 - Remote Code Execution via Office Conversion Settings

Title source: llm
STIX 2.1

Description

An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function.

Scores

CVSS v3 8.8
EPSS 0.0094
EPSS Percentile 56.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (3)
easycorp/zentao < 18.6
easycorp/zentao_biz < 8.6
easycorp/zentao_max < 4.7
Published Oct 10, 2023
Tracked Since Feb 18, 2026