Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3092 | Winter is a free, open-source content management system. Prior to 1.2.4, Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be rendered unescaped in the backend form, potentially allowing for a stored XSS attack. This issue has been patched in v1.2.4. |
Github GHSA |
GHSA-43w4-4j3c-jx29 | Winter CMS Stored XSS through Backend ColorPicker FormWidget |
Thu, 17 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-17T20:27:13.689Z
Reserved: 2023-12-26T17:23:22.236Z
Link: CVE-2023-52084
Updated: 2024-08-02T22:48:12.169Z
Status : Modified
Published: 2023-12-28T23:15:43.777
Modified: 2024-11-21T08:39:08.280
Link: CVE-2023-52084
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA