{"id":"CVE-2022-47745","details":"ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.","modified":"2026-04-10T04:56:38.565553Z","published":"2023-01-19T18:15:15.133Z","references":[{"type":"REPORT","url":"https://github.com/easysoft/zentaopms/issues/106"},{"type":"EVIDENCE","url":"https://github.com/l3s10n/ZenTaoPMS_SqlInjection"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/easysoft/zentaopms","events":[{"introduced":"562b983c697d3553f33e4b2a225c6f21f003d230"},{"fixed":"41d8faab5bc42969a697466597265ad6f3172672"},{"introduced":"0"},{"last_affected":"f4286ebdc08164ef17ecba64a8830f797101b52a"}],"database_specific":{"versions":[{"introduced":"16.4"},{"fixed":"18.0"},{"introduced":"0"},{"last_affected":"18.0-beta1"}]}}],"versions":["zentaopms_16.4","zentaopms_16.5.beta1","zentaopms_17.0","zentaopms_17.1","zentaopms_17.6","zentaopms_17.6.2","zentaopms_17.7","zentaopms_17.8","zentaopms_18.0.beta1","zentaopms_18.0.beta2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-47745.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}