CVE-2019-13294: Arox School-ERP

Critical severity, CVSS 9.8. EPSS: 18.8% chance of exploitation in the next 30 days.

AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.

Affected products

  • Arox School-ERP: affected versions not specified

Published 2019-07-04. Last modified 2026-06-17.