[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#Winter CMS

articleHIGH 7.1

Authenticated Backend Users Can Bypass Users Controller Permission Checks in Winter CMS

A vulnerability in Winter CMS allows authenticated backend users to bypass permission checks in the Users controller, enabling them to call arbitrary methods with attacker-controlled parameters. This issue, tracked as CVE-2026-35445, has a CVSS score of 7.1 and affects Winter CMS versions prior to 1.2.13. The vulnerability requires an attacker to have a valid backend user account with any level of access. Immediate patching or workarounds are recommended to prevent exploitation.

Aug 13, 20261 source