Zentao Authorized XSS Vulnerability(CVE-2023-46491)
ZentaoPMS Introduce
ZentaoPMS (Zen Project Management System) is an open source project management and collaboration tool designed to help teams better plan, track, and complete projects. It is a professional project management platform suitable for organizations of all sizes, including small and medium-sized enterprises and large enterprises. Some important features and functions of ZentaoPMS.
Vulnerability Description
ZenTao ZenTao Biz <=4.1.3 has a Cross Site Scripting (XSS).
Principle and recurrence of vulnerabilities
{cat_hide}
In the "Integration ->Version Library ->Client" function of Zentao biz version 4.1.3, user input data was not filtered, resulting in the execution of arbitrary JavaScript code.
Successfully executed Payload insertion in client parameters:

{/cat_hide}
最后更新于 2026-08-14 「部分内容存在时效性,如有失效请留言反馈」
除注明外为 Hack All Sec 的博客 原创文章,转载请注明出处。
本作品采用 知识共享署名-相同方式共享 4.0 国际许可协议 进行许可。
Hack All Sec 的博客