ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36942”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36942
Published
2026-01-27
CVSS:
8.7
ShadowTrackr CVSS:
6.3
Summary:
Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.