#4762 - Critical Security Vulnerability in Composr CMS
0 guests and 0 members have recently viewed this.
The top 3 point earners from 8th Feb 2026 to 15th Feb 2026.
| Gabri |
|
|
|---|---|---|
| Master Rat |
|
|
| PDStig |
|
|
There are no events at this time
Some people may be naive and provide web hosting for a Composr site, without realizing they are effectively giving any administrator of that site control of their hosting.
This is not unique to Composr by any means. Web interface installation of PHP-based addons is a very common feature in CMS and forum software, and a necessary process for the audience Composr is targeted for. Composr goes further with a remote shell, but there's no escalation because the same could be achieved by uploading malicious addons.
Just document this in the installation tutorial to make sure it is understood by those who do their research.