CVE-2022-4984

ZenTao Biz < 6.5, ZenTao Max < 3.0, ZenTao Open Source Edition < 16.5, and ZenTao Open Source Edition < 16.5.beta1 contain an SQL injection vulnerability in the login functionality. The application does not properly validate the account parameter on /zentao/user-login.html before using it in a database query. A remote unauthenticated attacker can exploit this issue to execute crafted SQL expressions and retrieve sensitive information from the backend database, including user and application data. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-07 UTC.
CVSS

No CVSS.

Configurations

No configuration.

History

13 Nov 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-13 20:15

Updated : 2025-11-14 16:42


NVD link : CVE-2022-4984

Mitre link : CVE-2022-4984

CVE.ORG link : CVE-2022-4984


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')