PT-2026-76552 · Git+2 · Winter+1
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Winter versions prior to 1.2.13
Description
Custom CSS provided through the Brand Settings Styles field is compiled by the LESS parser and rendered without sanitization on every backend page. This allows a user with the
backend.manage branding permission to perform a stored cross-site scripting attack against other backend users. To exploit this, an attacker must already possess trusted access to the backend with specific administrative permissions.Recommendations
Update to version 1.2.13.
Restrict the
backend.manage branding permission to only trusted administrators and developers.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Winter
Winter/Wn-Backend-Module