An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function.
| Software | From | Fixed in |
|---|---|---|
| easycorp / zentao_max | - | 4.7.x |
| easycorp / zentao_biz | - | 8.6.x |
| easycorp / zentao | - | 18.6.x |