CVE-2022-47745: Easycorp Zentao

High severity, CVSS 8.8. EPSS: 15.4% chance of exploitation in the next 30 days.

ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.

Affected products

  • Easycorp Zentao: from 16.4, before 18.0 (fixed in 18.0); version 18.0 only

Published 2023-01-19. Last modified 2026-06-17.