Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43fv-wgqf-rwjq

Опубликовано: 24 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.

EPSS

Процентиль: 50%
0.0067
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-434

Связанные уязвимости

nvd
около 1 месяца назад

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.

EPSS

Процентиль: 50%
0.0067
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-434