CVE-2026-2552
Published
CVSS v3
5.5
MEDIUM
CVSS v2
5.2
MEDIUM
Affected
1
PROJECT
Description
A vulnerability was identified in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/control.php of the component Committer. Such manipulation of the argument filePath leads to path traversal. Upgrading to version 21.7.9 can resolve this issue. The affected component should be upgraded.