CVE-2025-13787 Details
Description
A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 is sufficient to fix this issue. You should upgrade the affected component.
A horizontal privilege escalation vulnerability has been identified in ZenTao Project Management Software versions through 21.7.6-8564. The issue resides in the file module's delete function, located in module/file/control.php. The vulnerability allows unauthorized deletion of files by manipulating the fileID parameter, bypassing object-level permission checks. This flaw can be exploited remotely, leading to arbitrary file deletion, including attachments from other users' comments.
Users are advised to upgrade to ZenTao version 21.7.7, where this vulnerability has been fixed. A patch is also available for version 21.7.6.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ez-lbz/ez-lbz.github.io/issues/1 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| https://github.com/ez-lbz/ez-lbz.github.io/issues/1#issuecomment-3540423868 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| https://github.com/ez-lbz/ez-lbz.github.io/issues/1 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://github.com/ez-lbz/ez-lbz.github.io/issues/1#issuecomment-3540423868 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://vuldb.com/?ctiid.333791 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.333791 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.689892 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.zentao.net/extension-buyext-1601-download.html | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zentao zentao | < 21.7.7 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | CVE Modified | [email protected] |
| Sep 3, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 4, 2025 | Initial Analysis | [email protected] |
| Dec 1, 2025 | CVE Modified | CISA-ADP |
| Nov 30, 2025 | New CVE Received | [email protected] |