CVE-2023-4136: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafter Engine
Published Aug 3, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.
Affected Software
24 affected componentsFixes available
maven/org.craftercms:crafter-engine>=3.1.0<3.1.28
3.1.28
maven/org.craftercms:crafter-engine>=4.0.0<4.0.3
4.0.3
All of the following
Any of the following
CrafterCMS CrafterCMS>=3.1.0<=3.1.27
CrafterCMS CrafterCMS>=4.0.0<=4.0.2
Any of the following
Apple macOS
Apple macOS
Apple macOS
Linux Linux kernel
Linux Linux kernel
Linux Linux kernel
Microsoft Windows
Microsoft Windows
Microsoft Windows
CrafterCMS CrafterCMS>=3.1.0<=3.1.27
CrafterCMS CrafterCMS>=4.0.0<=4.0.2
Apple macOS
Apple macOS
Apple macOS
Linux Linux kernel
Linux Linux kernel
Linux Linux kernel
Microsoft Windows
Microsoft Windows
Microsoft Windows
Event History
Aug 3, 2023
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
DescriptionSeverityWeakness
Data Sourced
03:15 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-4136.
2
What is the severity rating of CVE-2023-4136?
CVE-2023-4136 has a severity rating of 6.1, which is considered high.
3
What is the affected software for CVE-2023-4136?
The affected software for CVE-2023-4136 is CrafterCMS version 4.0.0 through 4.0.2 and version 3.1.0 through 3.1.27.
4
What is the CWE ID for CVE-2023-4136?
The CWE ID for CVE-2023-4136 is CWE-79.
5
How can I fix the CVE-2023-4136 vulnerability?
To fix the CVE-2023-4136 vulnerability, it is recommended to update CrafterCMS to a version that is not affected by the vulnerability.