Critical severity9.8NVD Advisory· Published Feb 8, 2024· Updated Jun 17, 2026
CVE-2024-24202
CVE-2024-24202
Description
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.
Affected products
6- cpe:2.3:a:easycorp:zentao_biz:8.10:*:*:*:*:*:*:*
- cpe:2.3:a:easycorp:zentao_max:4.10:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: v18.10
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.