OSV 1.4.0 · github-reviewed · 修改于 2026-08-12 22:41
发布时间
2026-08-12 22:41
GitHub 审查时间
2026-08-12 22:41
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/08/GHSA-m7jc-g4rc-jmvh/GHSA-m7jc-g4rc-jmvh.json
The Backend Filter widget (Backend\Widgets\Filter) is vulnerable to SQL injection through the numberrange scope type when the scope is configured with a conditions key. An authenticated backend user with access to a list view containing a vulnerable filter scope can inject arbitrary SQL via the filter's AJAX handler, potentially gaining read access to the full database contents.
To exploit this, an attacker must have a valid backend account with access to a list view where a third-party plugin has registered a numberrange filter scope using the conditions configuration key. No built-in Winter CMS backend views use this scope type and configuration combination, so a vanilla installation without plugins is not exploitable.
This issue has been fixed in Winter CMS v1.2.13.
If users cannot upgrade, they may apply commit https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43 to your Winter CMS installation manually to resolve this issue.