Critical severity9.8NVD Advisory· Published Feb 8, 2024· Updated Jun 17, 2026
CVE-2024-24202
CVE-2024-24202
Description
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.
Affected products
6- ZenTao/ZenTao Community Editiondescription
- cpe:2.3:a:easycorp:zentao_biz:8.10:*:*:*:*:*:*:*
- cpe:2.3:a:easycorp:zentao_max:4.10:*:*:*:*:*:*:*
- Range: v18.10
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.