Winter 是一个基于 Laravel PHP 框架的免费、开源内容管理系统(CMS)。在 1.2.10 至 1.2.12 版本中,拥有 权限的已认证后台用户可以存储自定义标记样式,这些样式由 LESS 解析器编译后,在每个后台页面渲染时未经过消毒处理,从而导致存储型跨站脚本攻击(Stored XSS)。该问题已在 1.2.13 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-32257 | 8.1 HIGH | Winter: Stored XSS through Brand Settings custom styles |
| CVE-2026-35445 | 7.1 HIGH | Winter: Authenticated backend users can bypass Users controller permission checks |
| CVE-2026-32639 | 6.8 MEDIUM | Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and |
| CVE-2026-32593 | 5.9 MEDIUM | Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax |
| CVE-2026-54256 | 5.4 MEDIUM | Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attach |
| CVE-2026-63179 | 4.9 MEDIUM | Winter: Local File Inclusion through @import directives in LESS compilation of backend cus |
No comments yet