CVE-2023-52085
MEDIUM 5.4EPSS 30.2%
Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the compilation of custom stylesheets via LESS. This had the potential to lead to a Local File Inclusion vulnerability. This issue has been patched in v1.2.4.
- CVSS v3.1
- 5.4 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N - CVSS v3.1
- 3.3 LOW
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N - CVSS v3.1
- 3.3 LOW
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N - EPSS
- 30.17% chance of exploitation in the next 30 days, 98th percentile
- Nuclei
- medium · CWE-22
- Published
- 2023-12-29
- Updated
- 2024-08-02