top of page
perceptive_background_267k.jpg

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' paramet…

Published:

2 februari 2026 om 23:00:00

Alert date:

3 februari 2026 om 23:08:48

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

CVE-2020-37088 affects School ERP Pro 1.0, allowing unauthenticated attackers to read arbitrary files through a file disclosure vulnerability. The vulnerability is exploited by manipulating the 'document' parameter in download.php. Attackers can use directory traversal paths to access sensitive configuration files. This enables unauthorized access to system credentials and configuration information. The vulnerability allows complete bypass of authentication controls for file access.

Technical details

Mitigation steps:

Affected products:

School ERP Pro

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page