PT-2025-48391 · Zentao · Zentao

·

CVE-2025-13789

·

Published

2025-11-30

·

Updated

2025-12-04

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ZenTao versions up to 21.7.6-8564
Description A server-side request forgery condition exists in ZenTao. The issue is related to the makeRequest function within the module/ai/model.php file. Manipulation of the Base argument can trigger the issue. The attack can be launched remotely. The exploit has been made public.
Recommendations Upgrade to version 21.7.6 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13789

Affected Products

Zentao