THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-13789 (MEDIUM 6.3) — A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and co

[NVD] CVE-2025-13789 (MEDIUM 6.3) — A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and co

lownvdPublished 2025-11-30

CVE-2025-13789 CVSS: 6.3 MEDIUM Published: 2025-11-30T14:16:29.640

A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. Upgrading to version 21.7.6 mitigates t

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-13789