← voltar
CVE-2020-37088

School ERP Pro 1.0 - Arbitrary File Read

CVSS 8.7 HIGHEPSS 2.6%CWE-22
School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
Arox · School ERP Pro

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →