CVE-2020-37088 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' paramet…
High CVSS: 8.7

CVE-2020-37088

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information.
Vendor
Arox
Product
School Erp Pro
CWE
CWE-22
Yayın Tarihi
2026-02-03 22:16:24
Güncelleme
2026-02-10 17:03:53
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar