Executive brief
Sunnet CTMS, a corporate training management system, contains a security flaw that allows logged-in users to perform unauthorized database operations. An attacker could exploit this to view sensitive employee data, modify training records, or delete critical information from the system's database. This could lead to significant data loss and compromise the integrity of corporate training and compliance records.
Technical details
A SQL injection vulnerability (CWE-89) exists in Sunnet CTMS (Corporate Training Management System) across all versions. The flaw allows a remote attacker with low-level authentication (PR:L) to bypass input sanitization and execute arbitrary SQL commands against the backend database. Successful exploitation enables the attacker to perform unauthorized data exfiltration, data manipulation, or complete deletion of database records. The vendor has reportedly issued a patch, and users are advised to contact Sunnet directly for the update.
Affected products
- Sunnet (旭聯科技) CTMS (Corporate Training Management System) All versions
Timeline
- 2026-04-30: advisory: Initial disclosure by TWCERT/CC
- 2026-05-02: disclosed: CVE published to NVD