Description
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.
Published: 2026-07-24
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the e‑paper draft upload function of SUNNET Corporate Training Management System version 10.3 and permits a remote authenticated administrative user to upload a specially crafted ZIP archive that contains a server‑executable file. Because the system does not validate the file type, the uploaded archive can be executed on the target server, giving the attacker full control of the host. This allows the attacker to run arbitrary commands on the server, potentially compromising confidentiality, integrity, and availability.

Affected Systems

The flaw affects SUNNET Technology Co., Ltd.’s Corporate Training Management System, specifically version 10.3. No other products or versions are mentioned as affected in the advisory.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity. The EPSS score of < 1% suggests that the probability of exploitation is low, and the vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires a user with administrative privileges to upload a malicious ZIP file through the web interface, after which the attacker can execute arbitrary commands on the server. The attack vector is remote but depends on existing privileged access.

Generated by OpenCVE AI on August 3, 2026 at 20:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑issued patch or upgrade to a version that removes the vulnerable upload functionality.
  • Restrict the upload endpoint to explicitly allow only safe file types and reject any executable or archive formats that could contain server‑side code.
  • If a patch is unavailable, limit the use of the e‑paper upload feature to users with the minimum necessary privileges or disable the feature entirely for administrative accounts.

Generated by OpenCVE AI on August 3, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://zuso.ai/advisory cve-icon cve-icon
History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Sun.net
Sun.net corporate Training Management System
Vendors & Products Sun.net
Sun.net corporate Training Management System

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Description An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.
Title SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H'}


Subscriptions

Sun.net Corporate Training Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: ZUSO ART

Published:

Updated: 2026-07-24T12:33:09.459Z

Reserved: 2026-01-26T07:42:53.159Z

Link: CVE-2026-24727

cve-icon Vulnrichment

Updated: 2026-07-24T12:33:05.317Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T09:16:24.520

Modified: 2026-07-28T16:07:15.840

Link: CVE-2026-24727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:45:03Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type