An unrestricted upload of file with dangeroustype vulnerability in the e-paper draft upload function of SUNNET CorporateTraining Management System through v10.3 allows remote authenticated users withadministrator privileges to execute arbitrary commands by uploading a craftedZIP archive containing a server-executable file.
Contact SUNNET Technology for version updates.
Kuang Ming Chang of ZUSO ART