Local File Inclusion Vulnerability in Winter CMS by Winter
CVE-2026-79773
6.9MEDIUM
What is CVE-2026-79773?
Winter CMS versions before 1.2.13 are susceptible to a local file inclusion vulnerability in the JavascriptImporter filter. This flaw allows authenticated users with the 'cms.manage_assets' permission to exploit the vulnerability by including directives in theme JavaScript assets. By doing so, they can access server-readable files, such as sensitive configuration files, leveraging the combine route to deliver the output to unauthenticated users, which could lead to exposure of critical data like application keys and database credentials.
Affected Version(s)
winter 0 < 1.2.13
winter 1.2.13
