PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jun 2, 2025

CVE-2023-4136 Scanner

CVE-2023-4136 Scanner - Cross-Site Scripting vulnerability in CrafterCMS Engine

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-4136
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
CrafterCMSby CrafterCMS
4.0.0
Updated Aug 22, 2026View on NVD →
Detail

CrafterCMS Engine is a popular content management system used by organizations to manage digital content and deliver personalized digital experiences. It is widely used by businesses to create, manage, and deliver content-rich sites and applications. CrafterCMS allows teams to work collaboratively on content creation, publishing, and digital experience management. It provides flexibility with decoupled architecture and cloud-native capabilities, making it suitable for various deployment scenarios. Organizations leverage CrafterCMS to enhance engagement with users through tailored content delivery. Its comprehensive features help enterprises efficiently manage and scale their digital experiences.

Cross-Site Scripting (XSS) is a vulnerability that enables attackers to inject malicious scripts into web applications viewed by other users. In the context of CrafterCMS Engine, this vulnerability arises due to improper handling of user input in the 'transformerName' parameter. As a result, attackers can execute arbitrary JavaScript code within the browser of users interacting with the affected endpoint. This vulnerability could lead to unauthorized actions on behalf of the user, data theft, or session hijacking. XSS vulnerabilities are critical as they exploit the trust between a user and a web application, compromising user data and interactions.

The vulnerability in CrafterCMS Engine is located in the '/api/1/site/url/transform' endpoint. Attackers can exploit the 'transformerName' parameter by crafting a URL with malicious script content. When this URL is accessed, the crafted script is executed in the user's browser, potentially leading to the exploitation of user sessions. Due to improper input validation and output encoding, attackers can deliver the script through a simple GET request. Successful exploitation requires the user to load a page with the malicious URL, making user interaction a key aspect. This vulnerability underscores the importance of robust input validation within web applications.

If exploited, the XSS vulnerability in CrafterCMS Engine can have several adverse effects. Malicious actors could execute arbitrary scripts that hijack user sessions, steal sensitive information such as cookies, or redirect users to malicious sites. Users' trust in the application could be severely impacted, leading to reputational damage for the organization. Additionally, unauthorized actions could be performed on behalf of the user, leading to further security compromises. These consequences highlight the critical need for organizations to address XSS vulnerabilities promptly to protect user security and privacy.

REFERENCES

Solution Advice
  • Upgrade to the latest version of CrafterCMS Engine that addresses this vulnerability.
  • Implement proper input validation and output encoding to prevent script injection.
  • Conduct regular security assessments to identify and mitigate potential vulnerabilities.
  • Educate users about the risks of interacting with untrusted URLs and provide guidance on safe browsing practices.
  • Implement security headers to protect web applications against common vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-4136 Scanner - Cross-Site Scripting vulnerability in CrafterCMS Engine | S4E