PT-2026-5823 · Victoralagwu+1 · Cmssite+1

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2020-37072

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Victor CMS version 1.0
Description A stored cross-site scripting issue exists in the 'comment author' POST parameter. This allows attackers to submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in the browsers of users who view the comments.
Recommendations As a temporary workaround, restrict or sanitize the input of the comment author parameter in the comment submission form. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-37072

Affected Products

Cmssite
Victor Cms