CVSS v3
9.8
CRITICAL
EPSS Score
1.0 %
exploit probability
CISA KEV
No
known exploited
Exploitation
poc
SSVC status
Description
School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.
Technical details
- CVSS v3 Vector
- 3.1
- Published
- 2026-02-03
- Last Modified
- 2026-02-10
Frequently asked questions
What is CVE-2020-37090?
School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.
Is CVE-2020-37090 actively exploited?
A proof-of-concept exploit exists for CVE-2020-37090, but active exploitation has not been confirmed at this time.
What is the CVSS score for CVE-2020-37090?
CVE-2020-37090 has a CVSS v3 base score of 9.8 (CRITICAL severity), with vector string 3.1.
Is CVE-2020-37090 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2020 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).