School ERP Pro Path Traversal Vulnerability Allowing Arbitrary File Read

Vulnerability

A file disclosure vulnerability has been identified in School ERP Pro version 1.0. This vulnerability allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. By supplying directory traversal paths, attackers can access sensitive configuration files to retrieve system credentials and other confidential information.

Impact

Exploitation of this vulnerability leads to unauthorized access to arbitrary files, including sensitive configuration files that may contain system credentials.

Reproduction

To reproduce this vulnerability, send a request to download.php with a crafted 'document' parameter that includes directory traversal sequences. This will bypass normal file access restrictions and allow the retrieval of files outside the intended directory.

Added: Feb 3, 2026, 10:40 PM
Updated: Feb 3, 2026, 10:40 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
9.5
remediation
0.0
relevance
2.5
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.