🛡️ GHSA-q37h-jhf3-85cj — winter
Description
Bypass of CMS Safe Mode Security Feature
Impact
Authenticated users with permissions to create or modify theme template objects through the backend "CMS" editor can exploit this vulnerability to bypass the cms.enableSafeMode security feature if enabled (disables modification of PHP code through the web interface when enabled).
This is only an issue for Winter CMS instances that rely on the Safe Mode security feature to prevent privileged users from modifying the PHP code of CMS theme template objects through the web interface.
CVSS v3.1 Vector: [AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C&version=3.1)
Patches
Issue has been fixed in v1.0.475, v1.1.9, & v1.2.
Workarounds
Apply https://github.com/wintercms/storm/commit/03eb5ce3f2a271670574802b914f7bcaf07663c1 manually if unable to upgrade to v1.0.475, v1.1.9, or v1.2.0.
References
See https://github.com/octobercms/october/security/advisories/GHSA-79jw-2f46-wv22/.
Credit to [David Miller](https://github.com/cydave) for reporting the issue.
For more information
If you have any questions or comments about this advisory:
- Email us at [[email protected]](mailto:[email protected])
Affected software
GHSA-q37h-jhf3-85cj is recorded against 1 package.
- wintercms/winter (from 1.1.0 up to 1.1.9)
Timeline and source
Published on 15 July 2022 and last revised on 8 December 2024. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| wintercms/winter | 1.1.0 | 1.1.9 |
References
Similar Threats
- High CVE-2024-29686
- Low CVE-2023-37269
- High CVE-2022-39357
Free Vulnerability Check
Is your site affected by GHSA-q37h-jhf3-85cj?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against GHSA-q37h-jhf3-85cj and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.