Arox School ERP Pro是Arox公司的一个一站式自动化管理平台。 Arox School ERP Pro 1.0版本存在代码问题漏洞,该漏洞源于消息附件功能存在文件上传漏洞,可能导致学生上传任意PHP文件到消息系统,从而在服务器上执行远程代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arox | School ERP Pro | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-37089 | 8.2 HIGH | School ERP Pro 1.0 - 'es_messagesid' SQL Injection |
| CVE-2020-37088 | 7.5 HIGH | School ERP Pro 1.0 - Arbitrary File Read |
| CVE-2020-37084 | School ERP Pro 1.0 Admin Profile Photo Upload Remote Code Execution Vulnerability |
No comments yet