Winter CMS 是基于 Laravel PHP 框架构建的内容管理系统。在 1.2.12 及之前的版本中,经过身份验证的后端用户可通过在由后端编译的 LESS 源代码中注入 (内联)指令,泄露 PHP 进程可读的任意文件。这是因为 LESS 解析器在实例化时未配置安全的 import 解析器(safe import resolver),当没有匹配到允许的根目录时,会回退使用攻击者提供的原始路径。 该缺陷可通过四个共享相同根本原因的入口点触发: 1. 品牌设置(Brand Settings)中的 字段; 2.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32257 | 8.1 HIGH | Winter: Stored XSS through Brand Settings custom styles |
| CVE-2026-32258 | 8.1 HIGH | Winter: Stored XSS through Editor Settings custom styles |
| CVE-2026-35445 | 7.1 HIGH | Winter: Authenticated backend users can bypass Users controller permission checks |
| CVE-2026-32639 | 6.8 MEDIUM | Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and |
| CVE-2026-32593 | 5.9 MEDIUM | Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax |
| CVE-2026-54256 | 5.4 MEDIUM | Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attach |
No comments yet