Beveiligingsadvies

CVE-2020-37089

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-02-03 22:01:50
Laatst bijgewerkt 2026-03-05 01:27:51
Toegewezen door VulnCheck
CVSS-score 8.2
Status PUBLISHED

Beschrijving

School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries through GET requests. Attackers can exploit the vulnerable parameter by injecting crafted SQL statements to potentially extract, modify, or delete database information.