vendor:
School ERP Pro
by:
Besim ALTINOK
7.5
CVSS
HIGH
Arbitrary File Read
22
CWE
Product Name: School ERP Pro
Affected Version From: latest version
Affected Version To: latest version
Patch Exists: NO
Related CWE: N/A
CPE: a:arox:school_erp_pro
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Xampp
2020
School ERP Pro 1.0 – Arbitrary File Read
School ERP Pro 1.0 is vulnerable to an arbitrary file read vulnerability. An attacker can exploit this vulnerability by sending a crafted HTTP request containing a maliciously crafted document parameter to the vulnerable download.php script. This can allow an attacker to read sensitive files from the server.
Mitigation:
The vendor should ensure that user input is properly sanitized and validated before being used in file operations.