PT-2023-15472 · Zentao · Zentao

L3S10N

·

Published

2023-01-19

·

Updated

2025-04-04

·

CVE-2022-47745

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZenTao versions 16.4 through 18.0.beta1
Description The issue allows for SQL injection after logging in with any user, by constructing a special request and sending it to the importNotice function. This enables the completion of SQL injection.
Recommendations For versions 16.4 through 18.0.beta1, consider disabling the importNotice function until a patch is available to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-47745

Affected Products

Zentao