Record summary

CVE-2023-4136 has a selected CVSS score of 7.4 (high); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 9, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List4.0.0 to ≤ 4.0.2affected
3.1.0 to ≤ 3.1.27affected
GitHub Advisory4.0.0 to < 4.0.3 · Fixed in 4.0.3affected
3.1.0 to < 3.1.28 · Fixed in 3.1.28affected

Nuclei templates

1
ProjectDiscoveryMEDIUMCrafterCMS Engine - Cross-Site ScriptingCVSS 6.1

CrafterCMS Engine is vulnerable to reflected cross-site scripting (XSS) via the transformerName parameter in the /api/1/site/url/transform endpoint, allowing attackers to execute arbitrary JavaScript in the context of the user.

Impact

Unauthenticated attackers can inject malicious JavaScript through the transformerName parameter in various API endpoints to steal CrafterCMS user credentials and session data.

Remediation

Update CrafterCMS Engine to the latest version that addresses this vulnerability.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023craftercmsxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Shodan: http.html:"craftercms"
FOFA: body="craftercms"

Source: ProjectDiscovery

References

5