Back to CVE List

CVE-2026-24727

Vulnerability Description

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-434
Source
NVD
Vendor
SUNNET Technology Co., Ltd.
Product
Corporate Training Management System

External References

Discussion (0)

Add Comment

No comments yet. Be the first!