Security Advisory

CVE-2020-37089

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-02-03 22:01:50
Last updated 2026-03-05 01:27:51
Assigner VulnCheck
State PUBLISHED

Description

School ERP Pro 1.0 contains a SQL injection vulnerability in the es_messagesid parameter that allows attackers to manipulate database queries through GET requests. Attackers can exploit the vulnerable parameter by injecting crafted SQL statements to potentially extract, modify, or delete database information.