An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://zuso.ai/advisory |
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-24 09:16
Updated : 2026-07-28 16:07
NVD link : CVE-2026-24727
Mitre link : CVE-2026-24727
CVE.ORG link : CVE-2026-24727
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
