📦 Ehrd Ctms

by Sun.net

🔍 What is Ehrd Ctms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-54946

CRITICAL CVSS 9.8 Aug 30, 2025

A SQL injection vulnerability in SUNNET Corporate Training Management System allows remote attackers to execute arbitrary SQL commands. This could lead to data theft, system compromise, or complete da...

CVE-2025-54944

CRITICAL CVSS 9.8 Aug 30, 2025

This vulnerability allows remote attackers to upload malicious files to SUNNET Corporate Training Management System, potentially leading to arbitrary code execution. It affects all systems running ver...

CVE-2025-54942

CRITICAL CVSS 9.8 Aug 30, 2025

This vulnerability allows remote attackers to access deployment functionality in SUNNET Corporate Training Management System without authentication. Attackers can potentially deploy malicious code or ...

CVE-2024-10440

CRITICAL CVSS 9.8 Oct 28, 2024

The eHDR CTMS from Sunnet contains a SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL commands. This enables attackers to read, modify, or delete datab...

CVE-2024-10438

HIGH CVSS 7.5 Oct 28, 2024

The eHRD CTMS from Sunnet has an authentication bypass vulnerability that allows unauthenticated remote attackers to access restricted functionalities without valid credentials. Organizations using Su...

CVE-2023-24836

HIGH CVSS 8.8 Apr 27, 2023

SUNNET CTMS has a path traversal vulnerability in its file upload function that allows authenticated users to upload and execute scripts in arbitrary directories. This enables remote code execution an...

CVE-2025-9567

MEDIUM CVSS 6.1 Sep 1, 2025

This is a reflected cross-site scripting (XSS) vulnerability in Sunnet's eHRD software that allows unauthenticated attackers to execute arbitrary JavaScript in users' browsers through phishing attacks...

CVE-2025-9568

MEDIUM CVSS 6.1 Sep 1, 2025

Sunnet eHRD software contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in users' browsers through phishing links. This affec...

CVE-2025-9569

MEDIUM CVSS 6.1 Sep 1, 2025

This is a reflected cross-site scripting (XSS) vulnerability in Sunnet's eHRD software that allows unauthenticated attackers to execute arbitrary JavaScript in users' browsers through phishing attacks...

CVE-2025-3707

MEDIUM CVSS 6.5 May 2, 2025

The eHDR CTMS from Sunnet contains a SQL injection vulnerability that allows authenticated users with regular privileges to execute arbitrary SQL commands and read database contents. This affects orga...