CVE-2022-27478

HIGH

Victor Cms - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/k0xx11/Vulscve/blob/master/Victor1.0-rce.md

Scores

CVSS v3 8.8
EPSS 0.0321
EPSS Percentile 87.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
victor_cms_project/victor_cms 1.0
Published Apr 21, 2022
Tracked Since Feb 18, 2026