Vulnerability Description
School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arox | School Erp Pro | 1.0 |
Related Weaknesses (CWE)
References
- https://web.archive.org/web/20190612111732/https://sourceforge.net/projects/schoProduct
- https://web.archive.org/web/20200129123503/http://arox.in/Product
- https://www.exploit-db.com/exploits/48394ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/school-erp-pro-arbitrary-file-readThird Party Advisory
FAQ
What is CVE-2020-37088?
CVE-2020-37088 is a vulnerability with a CVSS score of 7.5 (HIGH). School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access...
How severe is CVE-2020-37088?
CVE-2020-37088 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-37088?
Check the references section above for vendor advisories and patch information. Affected products include: Arox School Erp Pro.