PT-2025-35338 · Unknown · Corporate Training Management System

Published

2025-08-30

·

Updated

2026-01-30

·

CVE-2025-54944

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SUNNET Corporate Training Management System versions prior to 10.11
Description An unrestricted file upload issue exists in SUNNET Corporate Training Management System. This allows remote attackers to upload files of dangerous types and potentially write malicious code to a specific file, leading to arbitrary code execution.
Recommendations Update SUNNET Corporate Training Management System to version 10.11 or later.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-54944

Affected Products

Corporate Training Management System