VYPR

school-erp-ultimate

by EMule X Ray

CVEs (1)

  • CVE-2020-37088HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.03

    School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to…