Security Advisory

CVE-2019-13294

9.8
CRITICAL

Vulnerability Description

AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.
Published Date July 4, 2019
Official Source NIST NVD Advisory