CVE-2020-28165

Publication date

2021-08-12 11:01:33

Family

mitre

State

PUBLISHED

Description

The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.