Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
AROX School-ERP Pro 访问控制错误漏洞
Vulnerability Description
AROX School-ERP Pro是一套基于Web的学校管理系统。该系统包括课程管理、考勤管理、财务管理、人力资源管理和考试管理等功能。 AROX School-ERP Pro中存在安全漏洞,该漏洞源于import_stud.php和upload_fille.php文件没有进行会话控制。攻击者可利用该漏洞在系统上执行命令。
CVSS Information
N/A
Vulnerability Type
N/A