winter/wn-system-module Security Advisories (3)
-
[HIGH] Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)
PKSA-wtw3-z7vh-tcrk GHSA-8cfw-pcwh-v63w
Affected version: >=1.2.7,<1.2.13
Reported by:
GitHub -
[MEDIUM] Winter: Local File Inclusion through =include directives in JavaScript asset compilation
PKSA-xv7p-39zk-tqqd GHSA-2223-f22x-24cq
Affected version: <1.2.13
Reported by:
GitHub -
[LOW] Winter CMS Stored XSS through privileged upload of Media Manager file followed by renaming
PKSA-j6xz-7bkh-y4wt CVE-2023-52083 GHSA-4wvw-75qh-fqjp
Affected version: <1.2.4
Reported by:
GitHub