Composr 10.0.30 allows Persistent XSS via a Usergroup name under the Security configuration.
- http://packetstormsecurity.com/files/157787/Composr-CMS-10.0.30-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2020/May/39
No PoCs found on GitHub currently.