CVE-2026-24727
SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.
| CWE | CWE-434 |
| Vendor | sunnet technology co., ltd. |
| Product | corporate training management system |
| Published | Jul 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for sunnet technology co., ltd. corporate training management system
Be the first to know when new unknown vulnerabilities affecting sunnet technology co., ltd. corporate training management system are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SUNNET Technology Co., Ltd. / Corporate Training Management System
0 โค v.10.3