PT-2026-76553 · Git+2 · Winter+1
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Winter versions 1.2.10 through 1.2.12
Description
Authenticated backend users with the
backend.manage editor permission can store custom Markup Styles via Settings → Editor Settings → Markup Styles. These styles are compiled by the LESS parser and rendered on every backend page without sanitization, enabling stored cross-site scripting (XSS). The issue occurs within the renderCss() function, which failed to sanitize the compiled CSS output.Recommendations
Update Winter versions 1.2.10 through 1.2.12 to version 1.2.13.
Restrict the
backend.manage editor permission to trusted administrators and developers only.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Winter
Winter/Wn-Backend-Module