PT-2026-5823 · Victoralagwu+1 · Cmssite+1
Published
2026-02-03
·
Updated
2026-02-03
·
CVE-2020-37072
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Victor CMS version 1.0
Description
A stored cross-site scripting issue exists in the 'comment author' POST parameter. This allows attackers to submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in the browsers of users who view the comments.
Recommendations
As a temporary workaround, restrict or sanitize the input of the
comment author parameter in the comment submission form. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cmssite
Victor Cms