The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-33121 The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.
Fixes

Solution

Please contact Sunnet for version updates or upgrades.


Workaround

No workaround given by the vendor.

History

Thu, 25 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Sun.net ehrd Ctms
CPEs cpe:2.3:a:sun.net:ehdr_ctms:*:*:*:*:*:*:*:* cpe:2.3:a:sun.net:ehrd_ctms:*:*:*:*:*:*:*:*
Vendors & Products Sun.net ehdr Ctms
Sun.net ehrd Ctms

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00137}

epss

{'score': 0.00158}


Thu, 31 Oct 2024 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Sun.net
Sun.net ehdr Ctms
CPEs cpe:2.3:a:sun.net:ehdr_ctms:*:*:*:*:*:*:*:*
Vendors & Products Sun.net
Sun.net ehdr Ctms

Mon, 28 Oct 2024 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Sunnet
Sunnet ehrd Ctms
CPEs cpe:2.3:a:sunnet:ehrd_ctms:*:*:*:*:*:*:*:*
Vendors & Products Sunnet
Sunnet ehrd Ctms
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Oct 2024 03:15:00 +0000

Type Values Removed Values Added
Description The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.
Title Sunnet eHRD CTMS - Insecure Direct Object Reference
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-10-28T12:50:33.935Z

Reserved: 2024-10-28T02:02:18.222Z

Link: CVE-2024-10439

cve-icon Vulnrichment

Updated: 2024-10-28T12:50:28.191Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-28T03:15:02.700

Modified: 2025-09-25T14:13:08.880

Link: CVE-2024-10439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.