Victor CMS 1.0 contains a file upload vulnerability that...
High severity
Unreviewed
Published
Jan 27, 2026
to the GitHub Advisory Database
•
Updated Jan 27, 2026
Description
Published by the National Vulnerability Database
Jan 27, 2026
Published to the GitHub Advisory Database
Jan 27, 2026
Last updated
Jan 27, 2026
Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.
References