PT-2023-31915 · Winter · Winter Cms

Cyber-Wo0Dy

·

Publicado

2023-12-28

·

Atualizado

2024-01-05

·

CVE-2023-52083

CVSS v3.1

2.0

Baixa

VetorAV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Winter CMS versions prior to 1.2.4
Description The issue allows users with the media.manage media permission to upload files to the Media Manager and rename them after uploading, potentially leading to a stored XSS attack. This is because media manager files were only sanitized on upload, not on renaming. The severity of this issue is considered low, as an attacker would already need to have trusted permissions in the Winter CMS backend and would need to convince the victim to directly visit the URL of the maliciously uploaded SVG. Additionally, the application would have to be using local storage where uploaded files are served under the same domain as the application itself instead of a CDN.
Recommendations For versions prior to 1.2.4, update to version 1.2.4 to ensure the system remains secure. As a temporary workaround for users unable to upgrade to v1.2.4, apply the patches manually from https://github.com/wintercms/winter/commit/2969daeea8dee64d292dbaa3778ea251e2a7e491.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-52083
GHSA-4WVW-75QH-FQJP

Produtos afetados

Winter Cms