CVE 8.7 HIGH

Sunnet|CTMS – SQL Injection_CVE-2026-7489

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

AI Analysis

SQL Injection vulnerability allowing remote attackers to inject arbitrary SQL commands

Basic Information

ID CVE-2026-7489
Source twcert
Published May 2, 2026 at 09:02

Affected Product

Vendor Sunnet
Product CTMS
Affected Versions Sunnet CTMS 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Sunnet
Product CTMS

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.