School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information. | |
| Title | School ERP Pro 1.0 - Arbitrary File Read | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-03T22:01:49.015Z
Updated: 2026-02-03T22:01:49.015Z
Reserved: 2026-02-01T13:16:06.487Z
Link: CVE-2020-37088
No data.
Status : Received
Published: 2026-02-03T22:16:24.677
Modified: 2026-02-03T22:16:24.677
Link: CVE-2020-37088
No data.