CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-54946

CVSS 9.3v4.0pub. 2025-08-30upd. 2026-01-30

A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.

🤖 AI Analysis
How it works

The vulnerability results from insufficient validation and sanitization of input data passed to SQL queries (CWE-89). A remote attacker can inject malicious SQL commands over the network without needing to have an account in the system or engaging a user. A properly crafted request allows manipulation of the logic of queries directed to the database.

Impact

An attacker can read, modify, or delete data stored in the system's database, including potentially sensitive employee and training data. Depending on the database configuration, it is also possible to take control of the database server.

Mitigation & patch

The system should be updated to version 10.11 or newer. Details are available in the manufacturer's references and in the ZUSO Security Advisory ZA-2025-14 (https://zuso.ai/advisory/za-2025-14).

Who is affected

SUNNET Corporate Training Management System (CTMS) in versions prior to 10.11

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sun.net Ehrd Ctms

    APP
    Sun.Net
    < 10.11
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-54942CRITICAL9.3PL ✓same product

Brak uwierzytelnienia w SUNNET CTMS — dostęp do funkcji wdrożeniowych

CVE-2025-54943CRITICAL9.3PL ✓same product

Brak autoryzacji w SUNNET CTMS umożliwia nieautoryzowane wdrożenie aplikacji

CVE-2025-54945CRITICAL10.0PL ✓same product

RCE poprzez external control of file path w SUNNET CTMS

CVE-2024-10440CRITICAL9.8PL ✓same product

SQL Injection w eHDR CTMS (Sunnet) umożliwia nieautoryzowany dostęp do bazy

CVE-2026-7489HIGH8.7same product

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject ...