CVE-2023-52084 Information
Dec 29, 2023
cve
Description
Winter is a free open-source content management system. Prior to 1.2.4 Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be rendered unescaped in the backend form potentially allowing for a stored XSS attack. This issue has been patched in v1.2.4.
Reference
https://github.com/wintercms/winter/security/advisories/GHSA-43w4-4j3c-jx29 https://github.com/wintercms/winter/commit/517f65dfae679b57575b047de13c5af48915a5ba
Share on: