Arox School ERP Pro是Arox公司的一个一站式自动化管理平台。 Arox School ERP Pro 1.0版本存在代码问题漏洞,该漏洞源于pre-editstudent.inc.php中的文件验证不当,可能导致经过身份验证的管理员用户上传任意PHP文件作为个人资料照片,从而在服务器上执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arox | School ERP Pro | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-37090 | 9.8 CRITICAL | School ERP Pro 1.0 - Remote Code Execution |
| CVE-2020-37089 | 8.2 HIGH | School ERP Pro 1.0 - 'es_messagesid' SQL Injection |
| CVE-2020-37088 | 7.5 HIGH | School ERP Pro 1.0 - Arbitrary File Read |
No comments yet