Vulnerabilities
Vulnerable Software
Arox:  Security Vulnerabilities
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
CVSS Score
6.5
EPSS Score
0.011
Published
2020-01-31
AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.
CVSS Score
9.8
EPSS Score
0.188
Published
2019-07-04
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
CVSS Score
9.8
EPSS Score
0.027
Published
2017-10-31


Contact Us

Shodan ® - All rights reserved