CVE-2020-26678: Vfairs
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP file on the server and gain code execution.
Affected products
- Vfairs Vfairs: version 3.3 only
Published 2021-05-26. Last modified 2026-07-09.