
CVE-2020-37089 School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries through GET requests. … https://www.cve.org/CVERecord?id=CVE-2020-37089
Post summary
CVE‑2020‑37089 discloses a SQL injection flaw in School ERP Pro 1.0 affecting the 'es_messagesid' parameter through GET requests.
