CVE-2020-37072

HIGH

Victor CMS 1.0 - XSS

Title source: llm
STIX 2.1

Description

Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in victim browsers.

Exploits (1)

exploitdb WORKING POC
by Kishan Lal Choudhary · textwebappsphp
https://www.exploit-db.com/exploits/48484

Scores

CVSS v3 7.2
EPSS 0.0004
EPSS Percentile 10.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
victor_cms_project/victor_cms 1.0
Published Feb 03, 2026
Tracked Since Feb 18, 2026