PT-2025-48391 · Zentao · Zentao

Ez-Lbz

·

Published

2025-11-30

·

Updated

2025-12-04

·

CVE-2025-13789

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ZenTao versions up to 21.7.6-8564
Description A server-side request forgery condition exists in ZenTao. The issue is related to the makeRequest function within the module/ai/model.php file. Manipulation of the Base argument can trigger the issue. The attack can be launched remotely. The exploit has been made public.
Recommendations Upgrade to version 21.7.6 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-13789

Affected Products

Zentao