CVE-2025-13787 is a critical improper privilege management vulnerability affecting ZenTao versions up to 21.7.6-8564. By manipulating the 'fileID' argument within the 'file::delete' function of the File Handler component, an unauthenticated attacker can remotely achieve high impact to integrity and availability. This vulnerability has a CVSS score of 9.1, indicating its severe nature. While no active exploitation, public exploit code, or significant community discussion has been observed, immediate upgrade to ZenTao version 21.7.7 is strongly recommended to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.7.7CPE matchmatch criteria | cpe:2.3:a:zentao:zentao:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.