Composr
cpe:2.3:a:composr_project:composr:*:*:*:*:*:*:*
- <= 10.0.34
A persistent cross-site scripting vulnerability has been identified in Composr CMS version 10.0.34. This issue allows authenticated administrators to inject malicious scripts via the banner management interface. XSS payloads inserted into the 'Description' field of the 'Add Banner' feature are executed for all visitors on the home page.
Exploitation of this vulnerability allows for persistent cross-site scripting, where injected scripts are executed in the context of the user visiting the home page.
To reproduce this vulnerability, log into Composr CMS 10.0.34 as an administrator. Navigate to the 'Add Banner' option and inject an XSS payload into the 'Description' field. After saving the banner, the injected script will execute for all users who visit the home page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.