Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
affected
Any version before 10.11
affected
Description
An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a specific file, which may lead to arbitrary code execution.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
Any version before 10.11
References
zuso.ai/advisory/za-2025-12