vendor:
Composr CMS
by:
Manuel Garcia Cardenas
5.4
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Composr CMS
Affected Version From: 10.0.30
Affected Version To: 10.0.30
Patch Exists: NO
Related CWE: CVE-2020-8789
CPE: a:compo.sr:composr_cms:10.0.30
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
Composr CMS 10.0.30 – Persistent Cross-Site Scripting
Has been detected a Persistent XSS vulnerability in Composr CMS, that allows the execution of arbitrary HTML/script code to be executed in the context of the victim user's browser.
Mitigation:
Disable until a fix is available.