winter/wn-backend-module Security Advisories for v1.2.13 (6)
-
[MEDIUM] Winter: Reflected XSS through the search query parameter in the backend Table widget
PKSA-5ts5-4cbq-8ssk GHSA-hq84-x37p-j6q5
Affected version: >=1.0.420,<=1.2.13
Reported by:
GitHub -
[MEDIUM] Winter: CSRF through AJAX handler names reachable as backend page actions
PKSA-r35b-91gt-bn2p GHSA-p2ch-c2c3-4xm5
Affected version: >=1.0.319,<1.2.14
Reported by:
GitHub -
[MEDIUM] Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles
PKSA-qr5m-g14w-86df GHSA-5cwr-5jxg-pcf6
Affected version: <=1.2.13
Reported by:
GitHub -
[HIGH] Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
PKSA-kk7w-bn2w-32z8 GHSA-fm29-4mq3-phg6
Affected version: <=1.2.13
Reported by:
GitHub -
[MEDIUM] Winter: My Account preview exposes another backend user's profile by record ID
PKSA-g4kv-c5yp-h2rm GHSA-mpmw-f6h6-3g26
Affected version: =1.2.13
Reported by:
GitHub -
[LOW] Winter: Stored XSS through Backend List widget image columns
PKSA-b1tx-fpj9-bp5n GHSA-7mpf-4465-7fc2
Affected version: >=1.1.0,<1.2.14
Reported by:
GitHub