CVE-2022-47745
Description
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.
References
ExploitThird Party Advisory
ExploitIssue TrackingThird Party Advisory
CvssV3 impact
Could not find any metrics
CvssV2 impact
Could not find any metrics