VYPR

School ERP Pro

by School ERP Ultimate

CVEs (1)

  • CVE-2020-37088Feb 3, 2026
    risk 0.00cvss epss 0.03

    School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to…