CVE-2017-15978: Arox School ERP PHP Script

Critical severity, CVSS 9.8. EPSS: 2.7% chance of exploitation in the next 30 days.

AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.

Affected products

  • Arox School ERP PHP Script: version 1.0 only

Published 2017-10-31. Last modified 2026-06-17.