Vulnerability Description
School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arox | School Erp Pro | 1.0 |
Related Weaknesses (CWE)
References
- https://web.archive.org/web/20190612111732/https://sourceforge.net/projects/schoProduct
- https://web.archive.org/web/20200129123503/http://arox.in/Product
- https://www.exploit-db.com/exploits/48392ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/school-erp-pro-admin-profile-photo-upload-rThird Party Advisory
FAQ
What is CVE-2020-37084?
CVE-2020-37084 is a vulnerability with a CVSS score of 7.2 (HIGH). School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers ca...
How severe is CVE-2020-37084?
CVE-2020-37084 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-37084?
Check the references section above for vendor advisories and patch information. Affected products include: Arox School Erp Pro.