Metrics
Affected Vendors & Products
Mon, 01 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Easycorp
Easycorp zentao |
|
| Vendors & Products |
Easycorp
Easycorp zentao |
Sun, 30 Nov 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. Upgrading to version 21.7.6 mitigates this issue. It is suggested to upgrade the affected component. | |
| Title | ZenTao model.php makeRequest server-side request forgery | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-11-30T13:32:16.964Z
Updated: 2025-12-01T15:48:42.607Z
Reserved: 2025-11-29T20:28:34.209Z
Link: CVE-2025-13789
Updated: 2025-12-01T15:48:35.441Z
Status : Awaiting Analysis
Published: 2025-11-30T14:16:29.640
Modified: 2025-12-01T15:39:33.110
Link: CVE-2025-13789
No data.