Vulnerability Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Craftercms | Craftercms | >= 3.1.0, <= 3.1.27 |
| Apple | Macos | - |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/174304/CrafterCMS-4.0.2-Cross-Site-Scriptin
- http://seclists.org/fulldisclosure/2023/Aug/30
- https://docs.craftercms.org/en/4.0/security/advisory.html#cv-2023080301Third Party Advisory
- http://packetstormsecurity.com/files/174304/CrafterCMS-4.0.2-Cross-Site-Scriptin
- http://seclists.org/fulldisclosure/2023/Aug/30
- https://docs.craftercms.org/en/4.0/security/advisory.html#cv-2023080301Third Party Advisory
FAQ
What is CVE-2023-4136?
CVE-2023-4136 is a vulnerability with a CVSS score of 7.4 (HIGH). Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affec...
How severe is CVE-2023-4136?
CVE-2023-4136 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4136?
Check the references section above for vendor advisories and patch information. Affected products include: Craftercms Craftercms, Apple Macos, Linux Linux Kernel, Microsoft Windows.