CVE-2024-10439: Sun.net Ehrd Ctms

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.

Affected products

  • Sun.net Ehrd Ctms: before 10.8 (fixed in 10.8)

Published 2024-10-28. Last modified 2026-06-17.