CVE-2025-13789 is a Server-Side Request Forgery (SSRF) vulnerability affecting ZenTao versions up to 21.7.6-8564, specifically within the makeRequest function of module/ai/model.php. This medium-severity vulnerability (CVSS 5.3) allows unauthenticated remote attackers to manipulate the 'Base' argument, potentially leading to information disclosure. While a public exploit exists, there is no evidence of active exploitation, and it has garnered minimal community discussion or media coverage. Upgrading to ZenTao version 21.7.6 is recommended to mitigate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.7.6CPE matchmatch criteria | cpe:2.3:a:zentao:zentao:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.