Project Subscriptions
No advisories yet.
Solution
The vendor should have issued a patch. If not yet received, please reach out to the vendor directly.
Workaround
No workaround given by the vendor.
Tue, 12 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sun.net
Sun.net ehrd Cpas Sun.net ehrd Ctms |
|
| CPEs | cpe:2.3:a:sun.net:ehrd_cpas:*:*:*:*:*:*:*:* cpe:2.3:a:sun.net:ehrd_ctms:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sun.net
Sun.net ehrd Cpas Sun.net ehrd Ctms |
Mon, 04 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sunnet
Sunnet cpas Sunnet ctms |
|
| Vendors & Products |
Sunnet
Sunnet cpas Sunnet ctms |
Mon, 04 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 02 May 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Title | Sunnet|CTMS and CPAS - Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-05-04T14:56:10.986Z
Reserved: 2026-04-30T09:01:05.760Z
Link: CVE-2026-7490
Updated: 2026-05-04T14:56:06.884Z
Status : Analyzed
Published: 2026-05-02T10:16:18.963
Modified: 2026-05-12T13:27:45.880
Link: CVE-2026-7490
No data.
OpenCVE Enrichment
Updated: 2026-05-04T19:44:28Z