Sunnet eHRD CTMS Arbitrary File Reading Vulnerability via Relative Path Traversal

Vulnerability

A vulnerability allowing arbitrary file reading has been identified in the eHRD CTMS application developed by Sunnet. This issue arises from a relative path traversal flaw, which remote attackers with administrator privileges can exploit to download arbitrary system files.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive system files, potentially allowing for further attacks or information disclosure.

Added: Sep 1, 2025, 4:20 AM
Updated: Sep 1, 2025, 4:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
2.8
remediation
0.0
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.