CVE-2020-37088
Unknown Unknown - Not Provided
Directory Traversal in School ERP Pro 1.0 Allows File Disclosure

Publication date: 2026-02-03

Last updated on: 2026-02-10

Assigner: VulnCheck

Description
School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-03
Last Modified
2026-02-10
Generated
2026-06-16
AI Q&A
2026-02-04
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
arox school_erp_pro 1.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

School ERP Pro 1.0 has a file disclosure vulnerability that allows attackers who are not authenticated to read arbitrary files on the system.

This is possible because the application does not properly validate the 'document' parameter in the download.php file, allowing attackers to manipulate it.

By using directory traversal techniques in this parameter, attackers can access sensitive configuration files, which may include system credentials and other important configuration information.

Impact Analysis

This vulnerability can have a significant impact because it allows unauthorized users to access sensitive files that should be protected.

Attackers could retrieve system credentials and configuration details, potentially leading to further compromise of the system or unauthorized access to sensitive data.

Since the vulnerability requires no authentication and has a high confidentiality impact (CVSS 3.1 score of 7.5 and CVSS 4.0 score of 8.7), it poses a serious security risk.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2020-37088. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart