PT-2026-81363 · Unknown · Winter Cms
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Winter CMS versions prior to 1.2.13
Description
An incomplete fix in
SystemTwigSecurityPolicy allows authenticated backend users with template-editing permissions to bypass Twig sandbox restrictions. This is achieved through method forwarding via Eloquent models and query builders using functions such as saveQuietly(), deleteQuietly(), increment(), decrement(), and newQuery(). Successful exploitation enables attackers to read and modify arbitrary database records, execute arbitrary SQL, and achieve remote code execution by injecting PHP into template code sections.Recommendations
Update Winter CMS to version 1.2.13 or later.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Winter Cms