A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.
The vulnerability results from insufficient validation and sanitization of input data passed to SQL queries (CWE-89). A remote attacker can inject malicious SQL commands over the network without needing to have an account in the system or engaging a user. A properly crafted request allows manipulation of the logic of queries directed to the database.
An attacker can read, modify, or delete data stored in the system's database, including potentially sensitive employee and training data. Depending on the database configuration, it is also possible to take control of the database server.
The system should be updated to version 10.11 or newer. Details are available in the manufacturer's references and in the ZUSO Security Advisory ZA-2025-14 (https://zuso.ai/advisory/za-2025-14).
SUNNET Corporate Training Management System (CTMS) in versions prior to 10.11
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSun.net Ehrd Ctms
APPSun.Net< 10.11
Related vulnerabilities
Brak uwierzytelnienia w SUNNET CTMS — dostęp do funkcji wdrożeniowych
Brak autoryzacji w SUNNET CTMS umożliwia nieautoryzowane wdrożenie aplikacji
RCE poprzez external control of file path w SUNNET CTMS
SQL Injection w eHDR CTMS (Sunnet) umożliwia nieautoryzowany dostęp do bazy
CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject ...