PKSA-m75m-ptnr-6hhr Security Advisory
-
[MEDIUM] Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
PKSA-m75m-ptnr-6hhr CVE-2026-32639 GHSA-5c4f-9pq9-6c77
Affected package: winter/wn-cms-module
Affected version: <=1.2.12
Reported by:
GitHub