CVE-2020-37090

high

Description

School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.

References

https://www.vulncheck.com/advisories/school-erp-pro-remote-code-execution

https://web.archive.org/web/20200129123503/http://arox.in/

https://web.archive.org/web/20190612111732/https://sourceforge.net/projects/school-erp-ultimate/

Details

Source: Mitre, NVD

Published: 2026-02-03

Updated: 2026-02-10

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00219