CVE-2026-24727
Vulnerability Description
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-434
Source
NVD
Vendor
SUNNET Technology Co., Ltd.
Product
Corporate Training Management System
Discussion (0)
Add Comment
No comments yet. Be the first!