PT-2026-5824 · Victoralagwu+1 · Cmssite+1

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2020-37073

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Victor CMS version 1.0
Description An authenticated file upload flaw allows administrators to upload PHP files containing arbitrary content via the user image parameter. This enables the upload of a malicious PHP shell to the '/img/' directory, allowing for the execution of system commands through the cmd parameter.
Recommendations Restrict the use of the user image parameter to prevent the upload of PHP files in Victor CMS version 1.0. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2020-37073

Affected Products

Cmssite
Victor Cms