SUNNET WMPro v5.0 and v5.1 has OS Command Injection
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 5.7%
exploitation probability
5.7%top 8% of all CVEs
observed exploitation
nono source reports it
The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.
Affected products
SUNNET · WMPro