Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafter Engine
CVE-2023-4136
6.1MEDIUM
What is CVE-2023-4136?
The vulnerability in CrafterCMS Engine allows for reflected Cross-Site Scripting (XSS), which could enable attackers to inject malicious scripts into web pages. This flaw affects CrafterCMS versions 4.0.0 through 4.0.2 and 3.1.0 through 3.1.27 across various platforms, including Windows, MacOS, and Linux. When exploited, this vulnerability can lead to unauthorized access to sensitive user data and potential manipulation of web content. Users are advised to implement the necessary security measures to mitigate risks associated with this vulnerability.
Affected Version(s)
CrafterCMS Windows 4.0.0 <= 4.0.2
CrafterCMS Windows 3.1.0 <= 3.1.27
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Egidio Romano <[email protected]>