Composr CMS 10.0.13 has XSS via the site_name parameter in a page=admin-setupwizard&type=step3 request to /adminzone/index.php.
No PoCs from references.
- https://github.com/0xT11/CVE-POC
- https://github.com/developer3000S/PoC-in-GitHub
- https://github.com/faizzaidi/Composr-CMS-10.0.13-Cross-Site-Scripting-XSS
- https://github.com/hectorgie/PoC-in-GitHub