2025-08-30

SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type

ZUSOART ID ZA-2025-12
CVE ID CVE-2025-54944
Vulnerability Type CWE-434: Unrestricted Upload of File with Dangerous Type
CVSS 4.0 Base CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N(6.9)
Description An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a specific file, which may lead to arbitrary code execution.
Vendor SUNNET Technology Co., Ltd.
Product
Category Version affected
Corporate Training Management System Before 10.11
Product Support Contact SUNNET Technology for version updates.
Release date 2025/08/30
Credit Cheng Ming Yang (TW1943) of ZUSO ART
top