CVE-2020-37084 - CVE House
Back to Database
Status published High CVE-2020-37084

School ERP Pro 1.0 Admin Profile Photo Upload Remote Code Execution Vulnerability

Vulnerability Description

School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the server.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37084

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Besim ALTINOK, İsmail BOZKURT

Affected Vendor

Affected Software

School ERP Pro
Vulnerable Versions:
1.0

Timeline

Official Publish: February 3rd, 2026
Last Modified: March 5th, 2026
Added to House: July 21st, 2026

CVSS Vectors

Weaknesses (CWE)