PT-2026-80755 · Unknown · Winter Cms
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Winter CMS versions prior to 1.2.13
Description
The backend
FileUpload form widget improperly trusts the file id POST parameter when resolving attachments. The getFileRecord() function resolves the provided ID against the global system files table without verifying if the file belongs to the widget's relation, parent record, or deferred-binding session. Since attachment IDs are sequential integers and easily enumerated, any authenticated backend user can target arbitrary attachment records. This allows an attacker to modify the title and description via the onSaveAttachmentConfig function, change the sort order via the onSortAttachments function, or access records through onLoadAttachmentConfig and onRemoveAttachment. Exploitation requires a valid authenticated backend session.Recommendations
Update Winter CMS to version 1.2.13 or later.
As a temporary mitigation, manually modify
modules/backend/formwidgets/FileUpload.php by replacing $this->getRelationModel()->find(post('file id')) with $this->getRelationObject()->withDeferred($this->sessionKey)->find(post('file id')) in the getFileRecord() function, and filter the posted sortOrder IDs in the onSortAttachments() function to include only those returned by $this->getRelationObject()->withDeferred($this->sessionKey)->pluck($keyName) before calling setSortableOrder().Exploit
Fix
Improper Access Control
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Winter Cms