← Back to browse · API

CVE-2020-7361

Severity
CRITICAL
CVSS
9.6
EPSS
0.17225
Risk score
44.43
CISA KEV
No
PoC
No
Published
2020-08-06
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2020-28488, GHSA-6WCP-GJ2X-5F4W
Products
EasyCorp:ZenTao Pro 8.8.2 ≤8.8.2
Sources
euvd EUVD-2020-28488

Description

The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.

References