An external control of file name or path vulnerability in...
Critical severity
Unreviewed
Published
Sep 25, 2025
to the GitHub Advisory Database
•
Updated Jan 30, 2026
Description
Published by the National Vulnerability Database
Aug 30, 2025
Published to the GitHub Advisory Database
Sep 25, 2025
Last updated
Jan 30, 2026
An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path.
References