Arox School ERP Pro是Arox公司的一个一站式自动化管理平台。 Arox School ERP Pro 1.0版本存在路径遍历漏洞,该漏洞源于download.php中的document参数存在文件泄露漏洞,攻击者可通过提供目录遍历路径来访问敏感配置文件,可能导致系统凭据和配置信息被检索。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arox | School ERP Pro | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-37090 | 9.8 CRITICAL | School ERP Pro 1.0 - Remote Code Execution |
| CVE-2020-37089 | 8.2 HIGH | School ERP Pro 1.0 - 'es_messagesid' SQL Injection |
| CVE-2020-37084 | School ERP Pro 1.0 Admin Profile Photo Upload Remote Code Execution Vulnerability |
No comments yet