Back to all
2026-07-24

SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type

ZUSOART ID
ZA-2026-03
CVE ID
CVE-2026-24727
Vulnerability Type
CWE-434: Unrestricted Upload of File with Dangerous Type
CVSS 4.0 Base
9.3
Description

An unrestricted upload of file with dangeroustype vulnerability in the e-paper draft upload function of SUNNET CorporateTraining Management System through v10.3 allows remote authenticated users withadministrator privileges to execute arbitrary commands by uploading a craftedZIP archive containing a server-executable file.

Vendor
SUNNET Technology Co., Ltd.
Product
Category
Version affected
Corporate Training Management System
Through v10.3
Mitigations

Contact  SUNNET Technology for version updates.

‍

Release date
2026-07-24
Credit

Kuang  Ming Chang of ZUSO ART

‍