CVE-2019-11062: Sun.net Wmpro

Critical severity, CVSS 9.8. EPSS: 5.7% chance of exploitation in the next 30 days.

The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.

Affected products

  • Sun.net Wmpro: version 5.0 only; version 5.1 only

Published 2019-07-11. Last modified 2026-06-17.