目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-54149— Winter 安全漏洞

一分钟漏洞结论

影响对象
wintercms winter
利用判断
存在公开或 AI PoC,应优先验证
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Winter是Winter开源的一款基于 Laravel PHP 框架的免费开源内容管理系统。 Winter 1.2.7之前版本、1.1.11之前版本和1.0.476之前版本存在安全漏洞,该漏洞源于用户能通过访问CMS模板部分绕过Twig文件的沙箱限制,进而未经授权修改或删除主题资源和模板,甚至操纵模型数据。

CVSS 8.5 · High EPSS 0.42% · P34

可能的 ATT&CK 技术 1 AI

T1059.001 · PowerShell
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2024-54149 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion
来源: CVE Program / CVE List V5
Vulnerability Description
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow users with access to the CMS templates sections that modify Twig files to bypass the sandbox placed on Twig files and modify resources such as theme customisation values or modify, or remove, templates in the theme even if not provided direct access via the permissions. As all objects passed through to Twig are references to the live objects, it is also possible to also manipulate model data if models are passed directly to Twig, including changing attributes or even removing records entirely. In most cases, this is unwanted behavior and potentially dangerous. To actively exploit this security issue, an attacker would need access to the Backend with a user account with any of the following permissions: `cms.manage_layouts`; `cms.manage_pages`; or `cms.manage_partials`. The Winter CMS maintainers strongly recommend that these permissions only be reserved to trusted administrators and developers in general. The maintainers of Winter CMS have significantly increased the scope of the sandbox, effectively making all models and datasources read-only in Twig, in versions 1.2.7, 1.1.11, and 1.0.476. Thse who cannot upgrade may apply commit fb88e6fabde3b3278ce1844e581c87dcf7daee22 to their Winter CMS installation manually to resolve the issue. In the rare event that a Winter user was relying on being able to write to models/datasources within their Twig templates, they should instead use or create components to make changes to their models.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
不完整的黑名单
来源: CVE Program / CVE List V5
Vulnerability Title
Winter 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Winter是Winter开源的一款基于 Laravel PHP 框架的免费开源内容管理系统。 Winter 1.2.7之前版本、1.1.11之前版本和1.0.476之前版本存在安全漏洞,该漏洞源于用户能通过访问CMS模板部分绕过Twig文件的沙箱限制,进而未经授权修改或删除主题资源和模板,甚至操纵模型数据。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
wintercms winter >= 1.2.0, < 1.2.7 -

二、漏洞 CVE-2024-54149 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级
Qwen3.6-35B-A3B · 4167 chars
Pro+ 专属包含:
漏洞复现靶场录像(真实沙箱构建 + 触发,独家)
漏洞原理深度分析
触发条件与影响面
完整可执行 POC 代码
利用链与缓解建议
POC 打包下载
每月 100+ 条 AI 生成额度

三、漏洞 CVE-2024-54149 的情报信息

请登录查看更多情报信息。

CVE-2024-54149 补丁与修复 (1)

CVE-2024-54149 厂商安全公告 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-54149

暂无评论


发表评论