CVE-2026-24727

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.
CVSS

No CVSS.

References
Link Resource
https://zuso.ai/advisory
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-24 09:16

Updated : 2026-07-28 16:07


NVD link : CVE-2026-24727

Mitre link : CVE-2026-24727

CVE.ORG link : CVE-2026-24727


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type