6.5
CVSSv3

CVE-2020-8504

Published: 31/01/2020 Updated: 05/02/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arox school management software php\\/mysql

Github Repositories

CSRF Exploits for School ERP Software

SchoolERPCSRF The School ERP System (sourceforgenet/projects/school-erp-ultimate/files/) is vulnerable to CSRF that leads to adding a new Admin user, and deleting an arbitrary user CVE-2020-8504 CVE-2020-8505 Proof of Concept code for adding an administrative user: <html> <body> <script>historypushState('', �