
CVE-2020-37084 School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing f… https://www.cve.org/CVERecord?id=CVE-2020-37084
Post summary
School ERP Pro 1.0 is vulnerable to remote code execution via arbitrary PHP file upload by authenticated admin users.
