High severity8.8NVD Advisory· Published Jan 27, 2026· Updated Jun 17, 2026
CVE-2020-36942
CVE-2020-36942
Description
Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:victor_cms_project:victor_cms:1.0:*:*:*:*:*:*:*
- Range: <=1.0
- Range: 1.0
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/49310nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/victor-cms-file-upload-to-rcenvdThird Party Advisory
News mentions
0No linked articles in our index yet.