Unrated severityNVD Advisory· Published Jan 27, 2026· Updated Jan 27, 2026
Victor CMS 1.0 - File Upload To RCE
CVE-2020-36942
Description
Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.
Affected products
1- Range: 1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/49310mitreexploit
- www.vulncheck.com/advisories/victor-cms-file-upload-to-rcemitrethird-party-advisory
News mentions
0No linked articles in our index yet.