Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34374 | A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://zuso.ai/advisory/za-2024-10 |
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 19 Dec 2024 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file. | |
| Title | SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ZUSO ART
Published:
Updated: 2024-12-20T18:01:19.504Z
Reserved: 2024-11-29T07:10:52.536Z
Link: CVE-2024-11984
Updated: 2024-12-20T18:01:01.433Z
Status : Received
Published: 2024-12-19T04:15:05.127
Modified: 2024-12-20T18:15:26.703
Link: CVE-2024-11984
No data.
OpenCVE Enrichment
No data.
EUVD