Winter CMS 是基于 Laravel PHP 框架构建的内容管理系统。在版本 1.2.12 及更早的版本中,后台的文件上传(FileUpload)表单控件在解析其操作的附件时,信任了由攻击者控制的 POST 参数。这使得拥有合法登录的后台用户能够读取和修改属于其他用户或记录的附件。 该控件的 查询在未验证该文件是否归属于控件自身的关系、父级记录或延迟绑定会话的情况下,将提交的 ID 与全局的 表进行匹配。由于所有附件共享同一个 File 模型和表,且附件 ID 为连续整数,易于枚举,因此任何能够访问包含 f
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32257 | 8.1 HIGH | Winter: Stored XSS through Brand Settings custom styles |
| CVE-2026-32258 | 8.1 HIGH | Winter: Stored XSS through Editor Settings custom styles |
| CVE-2026-35445 | 7.1 HIGH | Winter: Authenticated backend users can bypass Users controller permission checks |
| CVE-2026-32639 | 6.8 MEDIUM | Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and |
| CVE-2026-32593 | 5.9 MEDIUM | Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax |
| CVE-2026-63179 | 4.9 MEDIUM | Winter: Local File Inclusion through @import directives in LESS compilation of backend cus |
No comments yet