CVE-2020-37072
EUVD-2020-3101203.02.2026, 22:16
Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in victim browsers.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| victor_cms_project | victor_cms | 1.0 |
𝑥
= Vulnerable software versions