7.4 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): CHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafter Engine
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.
References
-
http://seclists.org/fulldisclosure/2023/Aug/30 x_transferred
-
http://seclists.org/fulldisclosure/2023/Aug/30 x_transferred
-
http://seclists.org/fulldisclosure/2023/Aug/30 x_transferred
-
http://seclists.org/fulldisclosure/2023/Aug/30 x_transferred
Affected products
- =<3.1.27
- =<4.0.2
Matching in nixpkgs
pkgs.haskellPackages.Control-Engine
A parallel producer/consumer engine (thread pool)
pkgs.perl538Packages.XMLXPathEngine
Re-usable XPath engine for DOM-like trees
pkgs.perl540Packages.XMLXPathEngine
Re-usable XPath engine for DOM-like trees
pkgs.perl538Packages.ZonemasterEngine
Tool to check the quality of a DNS zone
pkgs.perl540Packages.ZonemasterEngine
Tool to check the quality of a DNS zone