← back
CVE-2025-9570mediumCWE-23

Sunnet|eHRD CTMS - Arbitrary File Reading through Path Traversal

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Sunnet · eHRD CTMS