CVE-2020-37090Disclosure(arox / school_erp_pro)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • school_erp_pro

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
school_erp_pro

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-04: 2Technical Details · 2026-02-04: 202-04
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2020-37090 School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP… https://www.cve.org/CVERecord?id=CVE-2020-37090

    Post summary

    A file upload vulnerability in School ERP Pro 1.0 permits uploading arbitrary PHP files to the messaging system, potentially enabling remote code execution.

    00000134
    56.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2020-37090: CRITICAL] "Beware: School ERP Pro 1.0 vulnerable to file upload flaws. Attacker's PHP scripts pose risks via message attachments, enabling remote code execution on server. #cybersecurity"#cve,CVE-2020-37090,#cybersecurity https://cvefind.com/CVE-2020-37090

    Post summary

    The message announces a critical vulnerability in School ERP Pro 1.0, noting file upload flaws that allow remote code execution via message attachments, but does not provide a PoC or patch information.

    0000039
    583 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apparoxschool_erp_pro1.0--

Explore more