An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.
| Software | From | Fixed in |
|---|---|---|
| easycorp / zentao_max | 4.10 | 4.10.x |
| easycorp / zentao | 18.10 | 18.10.x |
| easycorp / zentao_biz | 8.10 | 8.10.x |