🔐 CVE Alert

CVE-2020-37084

UNKNOWN 0.0

School ERP Pro 1.0 Admin Profile Photo Upload Remote Code Execution Vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the server.

CWE CWE-434
Vendor arox
Product school erp pro
Published Feb 3, 2026
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for arox school erp pro

Be the first to know when new unknown vulnerabilities affecting arox school erp pro are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Arox / School ERP Pro
1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
exploit-db.com: https://www.exploit-db.com/exploits/48392 web.archive.org: https://web.archive.org/web/20200129123503/http://arox.in/ web.archive.org: https://web.archive.org/web/20190612111732/https://sourceforge.net/projects/school-erp-ultimate/ vulncheck.com: https://www.vulncheck.com/advisories/school-erp-pro-admin-profile-photo-upload-remote-code-execution-vulnerability

Credits

Besim ALTINOK, İsmail BOZKURT