← back
CVE-2020-37090

School ERP Pro 1.0 - Remote Code Execution

CVSS 8.7 HIGHEPSS 0.8%CWE-434
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
03 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Arox · School ERP Pro

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →