PT-2025-48391 · Zentao · Zentao
Ez-Lbz
·
Published
2025-11-30
·
Updated
2025-12-04
·
CVE-2025-13789
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ZenTao versions up to 21.7.6-8564
Description
A server-side request forgery condition exists in ZenTao. The issue is related to the
makeRequest function within the module/ai/model.php file. Manipulation of the Base argument can trigger the issue. The attack can be launched remotely. The exploit has been made public.Recommendations
Upgrade to version 21.7.6 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zentao