Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Winter vulnerable to Prototype Pollution in Snowboard framework
Vulnerability Description
Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it does not contain the Snowboard framework. This issue has been patched in v1.1.10 and v1.2.1. As a workaround, one may avoid this issue by following some common security practices for JavaScript, including implementing a content security policy and auditing scripts.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-1321
Vulnerability Title
Winter 安全漏洞
Vulnerability Description
Winter是基于 Laravel PHP 框架的免费、开源、自托管 CMS 平台。 Winter 1.1.8、1.1.9 和 1.2.0 版本存在安全漏洞,该漏洞源于 Snowboard 框架容易受到 Snowboard 主类及其插件加载器中的原型污染。
CVSS Information
N/A
Vulnerability Type
N/A