Back to Database
Status published
Medium
CVE-2025-54944
SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type
Vulnerability Description
An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a specific file, which may lead to arbitrary code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54944
Credits & Attribution
No credits recorded in the NVD database.
References
More from SUNNET Technology Co., Ltd.
View All →CVE-2025-54946
SUNNET Corporate Training Management System - SQL Injection
Critical
9.3
CVE-2025-54945
SUNNET Corporate Training Management System - External Control of File Name or Path
Critical
10
CVE-2025-54943
SUNNET Corporate Training Management System - Missing Authorization
Critical
9.3
CVE-2025-54942
SUNNET Corporate Training Management System - Missing Authentication for Critical Function
Critical
9.3
CVE-2025-31340
Wisdom Master Pro - Improper Control of Filename for Include/Require Statement in PHP Program
Critical
9.9
Affected Vendor
SUNNET Technology Co., Ltd.
View all reports →Affected Software
Corporate Training Management System
Vulnerable Versions:
0
Timeline
Official Publish:
August 30th, 2025
Last Modified:
January 30th, 2026
Added to House:
July 22nd, 2026