Description
Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the compilation of custom stylesheets via LESS. This had the potential to lead to a Local File Inclusion vulnerability. This issue has been patched in v1.2.4.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2x7r-93ww-cxrq | Winter CMS Local File Inclusion through Server Side Template Injection |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T22:48:12.111Z
Reserved: 2023-12-26T17:23:22.236Z
Link: CVE-2023-52085
No data.
Status : Modified
Published: 2023-12-29T00:15:50.300
Modified: 2024-11-21T08:39:08.413
Link: CVE-2023-52085
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA