Vulnerabilities (CVE)

Filtered by vendor Arox Subscribe
Filtered by product School Erp Pro
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-32118 1 Arox 1 School Erp Pro 2024-02-28 N/A 6.1 MEDIUM
Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.php.
CVE-2022-32119 1 Arox 1 School Erp Pro 2024-02-28 N/A 8.8 HIGH
Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.