File Upload Widget Vulnerability in Winter CMS by Winter
CVE-2026-54256
5.4MEDIUM
What is CVE-2026-54256?
In Winter CMS, versions up to and including 1.2.12, a vulnerability in the backend FileUpload form widget allows authenticated users to exploit the system. This occurs through the unvalidated handling of file_id POST parameters, which enables unauthorized modification of attachment records by targeting arbitrary attachments. Affected users can alter attachment titles and descriptions without proper authorization checks, as the widget incorrectly resolves file attachments. The issue can be exploited with an authenticated backend session, where CSRF tokens remain enforced, providing further security challenges. This flaw has been addressed in version 1.2.13.
Affected Version(s)
winter < 1.2.13
