Winter CMS Stored XSS through Backend ColorPicker FormWidget
CVE-2023-52084

2LOW

Key Information:

Vendor

Wintercms

Status
Vendor
CVE Published:
28 December 2023

What is CVE-2023-52084?

Winter is a free, open-source content management system. Prior to 1.2.4, Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be rendered unescaped in the backend form, potentially allowing for a stored XSS attack. This issue has been patched in v1.2.4.

Affected Version(s)

winter < 1.2.4

References

CVSS V3.1

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.