CVE-2020-37088 | Arox School ERP Pro 1.0 download.php document path traversal (Exploit 48394 / EUVD-2020-30989)
A vulnerability, which was classified as critical, has been found in Arox School ERP Pro 1.0. The affected element is an unknown function of the file download.php. Performing a manipulation of the argument document results in path traversal.
This vulnerability was named CVE-2020-37088. The attack may be initiated remotely. In addition, an exploit is available.