CVE 6.9 MEDIUM

SUNNET Corporate Training Management System – Unrestricted Upload of File with Dangerous Type_CVE-2025-54944

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Description

An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a specific file, which may lead to arbitrary code execution.

Basic Information

ID CVE-2025-54944
Source ZUSO ART
Published Aug 30, 2025 at 03:45

Affected Product

Vendor SUNNET Technology Co., Ltd.
Product Corporate Training Management System
Affected Versions SUNNET Technology Co., Ltd. Corporate Training Management System 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.