Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-52085 PoC — Winter 路径遍历漏洞

Source
Associated Vulnerability
Title:Winter 路径遍历漏洞 (CVE-2023-52085)
Description:Winter是基于 Laravel PHP 框架的免费、开源、自托管 CMS 平台。 Winter 1.2.4之前版本存在路径遍历漏洞,该漏洞源于允许攻击者通过提供给后端ColorPicker FormWidget的值的LESS编译来包含本地文件。
Description
Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the compilation of custom stylesheets via LESS. This had the potential to lead to a Local File Inclusion vulnerability. This issue has been patched in v1.2.4.
File Snapshot

id: CVE-2023-52085 info: name: Winter CMS Local File Inclusion - (LFI) author: sanineng sever ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.