Unrestricted File Upload in SUNNET Corporate Training Management System Allows Command Execution
CVE-2026-24727

9.3CRITICAL

What is CVE-2026-24727?

The SUNNET Corporate Training Management System contains a significant vulnerability in its e-paper draft upload function. This flaw permits remote authenticated users with administrator privileges to upload malicious ZIP files. If an attacker successfully uploads a ZIP archive containing an executable payload, they can execute arbitrary commands on the server, compromising the system's integrity. This underscores the importance of stringent file upload validation mechanisms to protect against unauthorized access and command execution.

Affected Version(s)

Corporate Training Management System 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.