Executive brief
Composr CMS, a content management system used for building social and interactive websites, contains a security vulnerability in its banner management system. An attacker with administrative access can inject malicious scripts into the banner description field. These scripts will then automatically run in the browsers of any visitor who views the website's home page, potentially allowing for session hijacking or the delivery of further malicious content to users.
Technical details
A persistent cross-site scripting (XSS) vulnerability exists in Composr CMS version 10.0.34 and earlier. The vulnerability is located in the 'Description' field of the 'Add banner' functionality within the banner management interface. An authenticated attacker with sufficient privileges to manage banners can inject arbitrary JavaScript payloads. Because this description is rendered on the home page without proper neutralization, the payload executes in the context of any user (including unauthenticated visitors) who accesses the site's front end. While the vendor has released newer versions (e.g., 10.0.52), users on version 10.0.34 should upgrade to the latest stable release to mitigate this risk.
Affected products
- Composr Composr CMS <= 10.0.34
Timeline
- 2020-12-03: disclosed: Initial discovery and exploit published by researcher Parshwa Bhavsar
- 2026-05-16: advisory: CVE published and NVD record created