EIP-2026-106112
PRE-CVEComposr CMS 10.0.30 - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106112. PoCs published by Manuel García Cárdenas.
AI-analyzed exploit summary This advisory details a persistent XSS vulnerability in Composr CMS 10.0.30, where the 'name' parameter in the Usergroup editor is not sanitized, allowing arbitrary script execution when a victim visits the 'Zone editor' area. The report includes a proof-of-concept payload and technical context.
Description
Composr CMS 10.0.30 - Persistent Cross-Site Scripting
Exploits (1)
This advisory details a persistent XSS vulnerability in Composr CMS 10.0.30, where the 'name' parameter in the Usergroup editor is not sanitized, allowing arbitrary script execution when a victim visits the 'Zone editor' area. The report includes a proof-of-concept payload and technical context.