漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ZenTao model.php makeRequest server-side request forgery
Vulnerability Description
A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. Upgrading to version 21.7.6 mitigates this issue. It is suggested to upgrade the affected component.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Nature Easy Soft Network Technology ZenTao 代码问题漏洞
Vulnerability Description
Nature Easy Soft Network Technology ZenTao是中国易软天创网络科技(Nature Easy Soft Network Technology)公司的一套开源项目管理软件。该软件包括产品管理、项目管理、质量管理和文档管理等功能。 Nature Easy Soft Network Technology 21.7.6-8564及之前版本存在代码问题漏洞,该漏洞源于对文件module/ai/model.php中参数Base的错误操作,可能导致服务端请求伪造。
CVSS Information
N/A
Vulnerability Type
N/A