HIGH
Sunnet|CTMS - SQL Injection
Published May 2, 2026
8.7
HIGHCVSS 4.0
EPSS 0.55%
Description
CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Affected products
-
- Version 0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The vendor should have issued a patch. If not yet received, please reach out to the vendor directly.
Weaknesses (1)
References (2)
- https://www.twcert.org.tw/en/cp-139-10895-25ca1-2.html third-party-advisoryThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-10894-1ac1f-1.html third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-10895-25ca1-2.html | third-party-advisoryThird Party Advisory | |
| https://www.twcert.org.tw/tw/cp-132-10894-1ac1f-1.html | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published May 2, 2026
Updated May 4, 2026
Reserved Apr 30, 2026
Link CVE-2026-7489
CISA Vulnrichment
Updated May 4, 2026