Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafter Engine
CVE-2023-4136
6.1MEDIUM
What is CVE-2023-4136?
The vulnerability in CrafterCMS Engine allows for reflected Cross-Site Scripting (XSS), which could enable attackers to inject malicious scripts into web pages. This flaw affects CrafterCMS versions 4.0.0 through 4.0.2 and 3.1.0 through 3.1.27 across various platforms, including Windows, MacOS, and Linux. When exploited, this vulnerability can lead to unauthorized access to sensitive user data and potential manipulation of web content. Users are advised to implement the necessary security measures to mitigate risks associated with this vulnerability.
Affected Version(s)
CrafterCMS Windows 4.0.0 <= 4.0.2
CrafterCMS Windows 3.1.0 <= 3.1.27
