VDB
Sign up
HIGH8.8

GHSA-8r5j-gm3j-cx9c

Winter CMS Server-Side Template Injection (SSTI) vulnerability

Details

Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/wintercms/winter
Introduced in: 0

No fixed version published yet for wintercms/winter (composer). Pin to a known-safe version or switch to an alternative.

References