CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Metrics
Affected Vendors & Products
References
History
Mon, 04 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sunnet
Sunnet cpas Sunnet ctms |
|
| Vendors & Products |
Sunnet
Sunnet cpas Sunnet ctms |
Mon, 04 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 02 May 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Title | Sunnet|CTMS and CPAS - Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published: 2026-05-02T09:06:25.153Z
Updated: 2026-05-04T14:56:10.986Z
Reserved: 2026-04-30T09:01:05.760Z
Link: CVE-2026-7490
Updated: 2026-05-04T14:56:06.884Z
Status : Awaiting Analysis
Published: 2026-05-02T10:16:18.963
Modified: 2026-05-05T20:14:57.860
Link: CVE-2026-7490
No data.
ReportizFlow