SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operation or disrupt service.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2023-04-27T00:00:00

Updated: 2024-08-02T11:03:19.319Z

Reserved: 2023-01-31T00:00:00

Link: CVE-2023-24836

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-27T02:15:09.243

Modified: 2023-05-08T17:41:05.390

Link: CVE-2023-24836

cve-icon Redhat

No data.