Executive brief
ZenTao is a popular project management and testing platform used to track tasks, bugs, test cases, and collaborative documents. A flaw in the file deletion function allows any authenticated user to delete arbitrary files belonging to other users by manipulating the file ID parameter, causing data loss and disrupting project workflows.
Technical details
The vulnerability is a horizontal privilege escalation (IDOR) in the `file::delete()` method in module/file/control.php (lines 310–333). The function accepts a user-supplied `fileID` parameter and deletes the corresponding file without verifying whether the current user has permission to delete it. The vulnerable code directly calls `$this->dao->delete()` after fetching the file by ID, with no authorization checks. An authenticated attacker can exploit this by crafting requests with arbitrary `fileID` values to delete files attached to other users' comments, tasks, bugs, or other objects. The fix is available in version 21.7.7 or later.
Affected products
- ZenTao ZenTao up to 21.7.6-8564
Timeline
- 2025-11-30: disclosed
- 2025-01-01: patched: Fix available in version 21.7.7