


Perceptive Security
SOC/SIEM Consultancy

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' paramet…
Published:
2 februari 2026 om 23:00:00
Alert date:
3 februari 2026 om 23:08:48
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
CVE-2020-37088 affects School ERP Pro 1.0, allowing unauthenticated attackers to read arbitrary files through a file disclosure vulnerability. The vulnerability is exploited by manipulating the 'document' parameter in download.php. Attackers can use directory traversal paths to access sensitive configuration files. This enables unauthorized access to system credentials and configuration information. The vulnerability allows complete bypass of authentication controls for file access.
Technical details
Mitigation steps:
Affected products:
School ERP Pro
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2020-37088
https://web.archive.org/web/20190612111732/https://sourceforge.net/projects/school-erp-ultimate/
https://web.archive.org/web/20200129123503/http://arox.in/
https://www.exploit-db.com/exploits/48394
https://www.vulncheck.com/advisories/school-erp-pro-arbitrary-file-read
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
