{"id":"CVE-2023-4136","details":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.","aliases":["GHSA-jfm4-3vv3-fm4v"],"modified":"2026-04-10T05:02:54.919788Z","published":"2023-08-03T15:15:34.167Z","references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/174304/CrafterCMS-4.0.2-Cross-Site-Scripting.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2023/Aug/30"},{"type":"ADVISORY","url":"https://docs.craftercms.org/en/4.0/security/advisory.html#cv-2023080301"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/craftercms/craftercms","events":[{"introduced":"8b4368c37a3ccdddbd37c1dd915d8352b3c6f1ef"},{"last_affected":"082fe5bb238e2a1a1f9af3bd760e0e34373cb57b"},{"introduced":"d5dabb5ca2dd63517f457201749aad71b02435f5"},{"last_affected":"340854716eb6b63398372e06c3de996ced8c6403"}],"database_specific":{"versions":[{"introduced":"3.1.0"},{"last_affected":"3.1.27"},{"introduced":"4.0.0"},{"last_affected":"4.0.2"}]}}],"versions":["v3.1.0","v3.1.1","v3.1.10","v3.1.11","v3.1.12","v3.1.15","v3.1.16","v3.1.17","v3.1.18","v3.1.19","v3.1.20","v3.1.21","v3.1.23","v3.1.24","v3.1.25","v3.1.26","v3.1.27","v3.1.4","v3.1.5","v3.1.6","v3.1.7","v3.1.8","v3.1.9","v4.0.0","v4.0.1","v4.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4136.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}