SCA: security update for wintercms/winter (GHSA-wjw2-4j7j-6gc3)

medium Tenable Self-Hosted Container Security Plugin ID 419979

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users
with the `backend.manage_branding` permission can upload SVGs as the application logo. Prior to version
1.2.3, SVG uploads were not sanitized, which could have allowed a stored cross-site scripting (XSS)
attack. To exploit the vulnerability, an attacker would already need to have developer or super user level
permissions in Winter CMS. This means they would already have extensive access and control within the
system. Additionally, to execute the XSS, the attacker would need to convince the victim to directly visit
the URL of the maliciously uploaded SVG, and the application would have to be using local storage where
uploaded files are served under the same domain as the application itself instead of a CDN. This is
because all SVGs in Winter CMS are rendered through an `img` tag, which prevents any payloads from being
executed directly. These two factors significantly limit the potential harm of this vulnerability. This
issue has been patched in v1.2.3 through the inclusion of full support for SVG uploads and automatic
sanitization of uploaded SVG files. As a workaround, one may apply the patches manually. (CVE-2023-37269)

See Also

https://github.com/advisories/GHSA-wjw2-4j7j-6gc3

Plugin Details

Severity: Medium

ID: 419979

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.14

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:N

CVSS Score Source: CVE-2023-37269

CVSS v3

Risk Factor: Medium

Base Score: 4.8

Temporal Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/7/2023

Vulnerability Publication Date: 7/7/2023

Reference Information

CVE: CVE-2023-37269

cwe: CWE-79