
CVE-2020-37090 School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP… https://www.cve.org/CVERecord?id=CVE-2020-37090
Post summary
A file upload vulnerability in School ERP Pro 1.0 permits uploading arbitrary PHP files to the messaging system, potentially enabling remote code execution.

