RULE(RULE ID:337799)

Rule General Information
Release Date: 2024-01-23
Rule Name: ZenTaoPMS 18.3 zahost Command Injection vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: ZenTaoPMS is a set of project management software developed by Nature Easy Soft Network Technology Company in order to solve the chaos and disorder in the management process of many enterprises.ZenTaoPMS V18.0-18.3 has a command injection vulnerability. This vulnerability is due to a new function of ZenTaoPMS. When a host is added, a malicious attacker can splice a malicious payload at the ip domain name, resulting in command injection.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.