CVE-2025-13789

A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. Upgrading to version 21.7.6 mitigates this issue. It is suggested to upgrade the affected component.
References
Link Resource
https://github.com/ez-lbz/ez-lbz.github.io/issues/2 Issue Tracking Exploit Vendor Advisory
https://github.com/ez-lbz/ez-lbz.github.io/issues/2#issue-3598317459 Issue Tracking Exploit Vendor Advisory
https://github.com/ez-lbz/ez-lbz.github.io/issues/2#issuecomment-3540247346 Issue Tracking Exploit
https://vuldb.com/?ctiid.333793 Permissions Required VDB Entry
https://vuldb.com/?id.333793 Third Party Advisory VDB Entry
https://vuldb.com/?submit.690728 Third Party Advisory VDB Entry
https://www.zentao.net/extension-viewext-6.html Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:zentao:zentao:*:*:*:*:*:*:*:*

History

04 Dec 2025, 16:36

Type Values Removed Values Added
First Time Zentao
Zentao zentao
CPE cpe:2.3:a:zentao:zentao:*:*:*:*:*:*:*:*
References () https://github.com/ez-lbz/ez-lbz.github.io/issues/2 - () https://github.com/ez-lbz/ez-lbz.github.io/issues/2 - Issue Tracking, Exploit, Vendor Advisory
References () https://github.com/ez-lbz/ez-lbz.github.io/issues/2#issue-3598317459 - () https://github.com/ez-lbz/ez-lbz.github.io/issues/2#issue-3598317459 - Issue Tracking, Exploit, Vendor Advisory
References () https://github.com/ez-lbz/ez-lbz.github.io/issues/2#issuecomment-3540247346 - () https://github.com/ez-lbz/ez-lbz.github.io/issues/2#issuecomment-3540247346 - Issue Tracking, Exploit
References () https://vuldb.com/?ctiid.333793 - () https://vuldb.com/?ctiid.333793 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.333793 - () https://vuldb.com/?id.333793 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.690728 - () https://vuldb.com/?submit.690728 - Third Party Advisory, VDB Entry
References () https://www.zentao.net/extension-viewext-6.html - () https://www.zentao.net/extension-viewext-6.html - Product

30 Nov 2025, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-30 14:16

Updated : 2025-12-04 16:36


NVD link : CVE-2025-13789

Mitre link : CVE-2025-13789

CVE.ORG link : CVE-2025-13789


JSON object : View

Products Affected

zentao

  • zentao
CWE
CWE-918

Server-Side Request Forgery (SSRF)