CVE-2020-37090: Arox School ERP Pro
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.
Affected products
- Arox School ERP Pro: version 1.0 only
Published 2026-02-03. Last modified 2026-06-17.