CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Metrics
Affected Vendors & Products
References
History
Sat, 02 May 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Title | Sunnet|CTMS and CPAS - Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-05-02T09:06:25.153Z
Reserved: 2026-04-30T09:01:05.760Z
Link: CVE-2026-7490
No data.
Status : Received
Published: 2026-05-02T10:16:18.963
Modified: 2026-05-02T10:16:18.963
Link: CVE-2026-7490
No data.
OpenCVE Enrichment
Updated: 2026-05-02T11:30:41Z