THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-13787 (MEDIUM 5.4) — A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launc

[NVD] CVE-2025-13787 (MEDIUM 5.4) — A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launc

lownvdPublished 2025-11-30

CVE-2025-13787 CVSS: 5.4 MEDIUM Published: 2025-11-30T11:15:48.567

A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 i

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-13787