


Perceptive Security
SOC/SIEM Consultancy

Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image …
Published:
2 februari 2026 om 23:00:00
Alert date:
3 februari 2026 om 23:08:48
Source:
nvd.nist.gov
Web Technologies
Victor CMS 1.0 contains an authenticated file upload vulnerability in the user_image parameter that allows administrators to upload PHP files with arbitrary content. Attackers can exploit this to upload malicious PHP shells to the /img/ directory and execute system commands by accessing the uploaded file with a 'cmd' parameter. This vulnerability allows for remote code execution through file upload bypass controls.
Technical details
Mitigation steps:
Affected products:
Victor CMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2020-37073
https://github.com/VictorAlagwu/CMSsite
https://www.exploit-db.com/exploits/48490
https://www.vulncheck.com/advisories/victor-cms-authenticated-arbitrary-file-upload
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
