ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37089”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37089
Published
2026-02-03
CVSS:
7.1
ShadowTrackr CVSS:
5.0
Summary:
School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries through GET requests. Attackers can exploit the vulnerable parameter by injecting crafted SQL statements to potentially extract, modify, or delete database information.