CVE-2024-24216

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
08/02/2024
Last modified:
08/05/2025

Description

Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:easycorp:zentao:*:*:*:*:*:*:*:* 18.0 (including) 18.10 (including)