---
id: CVE-2025-13787
title: A flaw has been found in ZenTao up to 21.7.6-8564
summary: >-
  A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the
  function file::delete of the file module/file/control.php of the component
  File Handler. Executing manipulation of the argument fileID can lead to
  improper pr…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-266
  - CWE-269
vendor: zentao
product: zentao
affected:
  - zentao < 21.7.7
patched:
  - zentao 21.7.7
published: '2025-11-30'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13787'
references:
  - url: 'https://github.com/ez-lbz/ez-lbz.github.io/issues/1'
    label: cna@vuldb.com
  - url: >-
      https://github.com/ez-lbz/ez-lbz.github.io/issues/1#issuecomment-3540423868
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.333791'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.333791'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.689892'
    label: cna@vuldb.com
  - url: 'https://www.zentao.net/extension-buyext-1601-download.html'
    label: cna@vuldb.com
  - url: 'https://github.com/ez-lbz/ez-lbz.github.io/issues/1'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://github.com/ez-lbz/ez-lbz.github.io/issues/1#issuecomment-3540423868
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00375
epssPercentile: 0.28635
ingestedAt: '2026-09-03T03:55:22.439Z'
---

## Overview

A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 is sufficient to fix this issue. You should upgrade the affected component.

## Affected

- `zentao < 21.7.7`

## Remediation

Upgrade past the affected range:

- `zentao 21.7.7`
