PT-2026-76556 · Git+2 · Winter+1

·

CVE-2026-35445

·

Published

2026-08-12

·

Updated

2026-08-27

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Winter CMS versions prior to 1.2.13
Description An issue exists where the backend fails to validate the handler name submitted via the handler POST field during form postbacks. While AJAX requests are validated against the on[A-Z][w+]* pattern, the postback path passes the handler value directly to the handler dispatcher without validation. This allows an authenticated backend user to invoke arbitrary controller methods, including protected, private, and action-prefixed ones, provided the controller has a public action or relaxes its $requiredPermissions check. For instance, the Users controller set $requiredPermissions to null for the myaccount action, enabling users without the backend.manage users permission to call sensitive methods such as update onDelete and update onManualPasswordReset().
Recommendations Update Winter CMS to version 1.2.13 or later. As a temporary workaround, validate the handler POST field against the on[A-Z][w+]* pattern in modules/backend/classes/Controller.php before it is passed to runAjaxHandler(). As a temporary workaround, remove the conditional that sets $requiredPermissions to null for the myaccount action in modules/backend/controllers/Users.php.

Exploit

Fix

Improper Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35445
GHSA-J5JQ-CR68-V2XX

Affected Products

Winter
Winter/Wn-Backend-Module