GHSA-m7jc-g4rc-jmvh: SQL Injection
Impact
The Backend Filter widget (Backend\Widgets\Filter) is vulnerable to SQL injection through the numberrange scope type when the scope is configured with a conditions key. An authenticated backend user with access to a list view containing a vulnerable filter scope can inject arbitrary SQL via the filter's AJAX handler, potentially gaining read access to the full database contents.
To exploit this, an attacker must have a valid backend account with access to a list view where a third-party plugin has registered a numberrange filter scope using the conditions configuration key. No built-in Winter CMS backend views use this scope type and configuration combination, so a vanilla installation without plugins is not exploitable.
Patches
This issue has been fixed in Winter CMS v1.2.13.
Workarounds
If users cannot upgrade, they may apply commit https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43 to your Winter CMS installation manually to resolve this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/winter/wn-backend-moduleto a version that resolves this vulnerability.Fixed in 1.2.13 - Upgrade
Upgrade
wintercms/winterto a version that resolves this vulnerability.Fixed in 1.2.13
Event History
Frequently Asked Questions
What is the severity of GHSA-m7jc-g4rc-jmvh?
The severity of GHSA-m7jc-g4rc-jmvh is medium with a score of 5.9.
What is the main impact of GHSA-m7jc-g4rc-jmvh?
GHSA-m7jc-g4rc-jmvh allows for SQL injection through the Backend Filter widget when configured with certain conditions.
How do I fix GHSA-m7jc-g4rc-jmvh?
To fix GHSA-m7jc-g4rc-jmvh, ensure you update to the latest version of the composer/winter/wn-backend-module which addresses this vulnerability.
Who is affected by GHSA-m7jc-g4rc-jmvh?
GHSA-m7jc-g4rc-jmvh affects authenticated backend users with access to list views containing vulnerable filter scopes.
What type of vulnerability is GHSA-m7jc-g4rc-jmvh?
GHSA-m7jc-g4rc-jmvh is classified as a SQL injection vulnerability.