go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

SUNNET CTMS - Path Traversal

TVN ID TVN-202302004
CVE ID CVE-2023-24836
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products SUNNET CTMS v7.0 1227
Description SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operation or disrupt service.
Solution Contact tech support from SUNNET
Credit Pin Wei, He (CHT Security)
Public Date 2023-04-10
Top