THREAT OPS › Threat News › [NVD] CVE-2025-13787 (MEDIUM 5.4) — A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launc
[NVD] CVE-2025-13787 (MEDIUM 5.4) — A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launc
CVE-2025-13787 CVSS: 5.4 MEDIUM Published: 2025-11-30T11:15:48.567
A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 i
Indicators of compromise
- CVE-2025-13787cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-13787