Unrestricted File Upload in SUNNET Corporate Training Management System Allows Command Execution
CVE-2026-24727
9.3CRITICAL
What is CVE-2026-24727?
The SUNNET Corporate Training Management System contains a significant vulnerability in its e-paper draft upload function. This flaw permits remote authenticated users with administrator privileges to upload malicious ZIP files. If an attacker successfully uploads a ZIP archive containing an executable payload, they can execute arbitrary commands on the server, compromising the system's integrity. This underscores the importance of stringent file upload validation mechanisms to protect against unauthorized access and command execution.
Affected Version(s)
Corporate Training Management System 0
