Composr CMS 10.0.34 Persistent Cross-Site Scripting via banners
Vulnerability Description
Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers with admin credentials can inject XSS payloads in the Description field of the Add banner functionality, which execute for all website visitors when they access the home page.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37237
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Parshwa Bhavsar
Affected Vendor
Compo
View all reports →