HIGH🇵🇱 Wersja polska

CVE-2022-39357

CVSS 8.1v3.1pub. 2022-10-26upd. 2024-11-21

Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it does not contain the Snowboard framework. This issue has been patched in v1.1.10 and v1.2.1. As a workaround, one may avoid this issue by following some common security practices for JavaScript, including implementing a content security policy and auditing scripts.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Wintercms Winter

    APP
    Wintercms
    1.1.81.1.91.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-27591CRITICAL9.9PL ✓same product

Winter CMS – privilege escalation przez modyfikację ról i uprawnień

CVE-2024-54149HIGH8.4same product

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS p...

CVE-2024-29686HIGH7.2same product

Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute ...

CVE-2026-22254NONE0same product

Winter to darmowy, open-source system zarządzania treścią (CMS) oparty na frameworku Laravel PHP. Wersje Winte...

CVE-2023-52085LOW3.3same product

Winter to darmowy, open-source'owy system zarządzania treścią. Użytkownicy mający dostęp do formularzy backend...