ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37084”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37084
Published
2026-02-03
CVSS:
8.6
ShadowTrackr CVSS:
6.1
Summary:
School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the server.