Impact
The vulnerability resides in the e‑paper draft upload function of SUNNET Corporate Training Management System version 10.3 and permits a remote authenticated administrative user to upload a specially crafted ZIP archive that contains a server‑executable file. Because the system does not validate the file type, the uploaded archive can be executed on the target server, giving the attacker full control of the host. This allows the attacker to run arbitrary commands on the server, potentially compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects SUNNET Technology Co., Ltd.’s Corporate Training Management System, specifically version 10.3. No other products or versions are mentioned as affected in the advisory.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score of < 1% suggests that the probability of exploitation is low, and the vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires a user with administrative privileges to upload a malicious ZIP file through the web interface, after which the attacker can execute arbitrary commands on the server. The attack vector is remote but depends on existing privileged access.
OpenCVE Enrichment