CVE-2026-24727
SUNNET Technology Co., Ltd. Corporate Training Management System
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.
- CVSS
- 9.3
- EPSS
- 0.67% 48.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.24