An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path.
| Software | From | Fixed in |
|---|---|---|
| sun.net / ehrd_ctms | - | 10.11 |