{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wn-backend-module/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["wn-backend-module"],"_cs_severities":["high"],"_cs_tags":["web-application","privilege-escalation","cms"],"_cs_type":"advisory","_cs_vendors":["Winter CMS"],"content_html":"\u003cp\u003eWinter CMS contains an improper input validation vulnerability (CVE-2026-35445) affecting the form postback mechanism. The vulnerability exists because the system fails to validate the \u003ccode\u003e_handler\u003c/code\u003e POST field submitted during form postbacks, whereas it correctly validates the \u003ccode\u003eX_WINTER_REQUEST_HANDLER\u003c/code\u003e header used in AJAX requests. This flaw allows an authenticated backend user to invoke restricted methods on controllers.\u003c/p\u003e\n\u003cp\u003eThe issue is particularly critical within the \u003ccode\u003eUsers\u003c/code\u003e controller, where the \u003ccode\u003e$requiredPermissions\u003c/code\u003e property was conditionally set to \u003ccode\u003enull\u003c/code\u003e for the \u003ccode\u003emyaccount\u003c/code\u003e action. An attacker with a low-privilege backend session can chain this postback bypass with the insecure permissions check to trigger sensitive administrative methods - including user deletion, restoration, and password resets - despite lacking the \u003ccode\u003ebackend.manage_users\u003c/code\u003e permission. All major versions of Winter CMS (1.0, 1.1, and 1.2) were vulnerable prior to version 1.2.13.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated backend users to escalate privileges and perform unauthorized administrative actions, including user deletion, restoration, and forced password resets, bypassing existing role-based access control (RBAC) configurations. This impacts the integrity and availability of user accounts and the overall security of the Winter CMS backend.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to Winter CMS version 1.2.13 or later to receive the core patch which enforces validation on the \u003ccode\u003e_handler\u003c/code\u003e POST field.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, apply the following manual workarounds:\u003c/li\u003e\n\u003cli\u003eModify \u003ccode\u003emodules/backend/classes/Controller.php\u003c/code\u003e to validate the \u003ccode\u003e_handler\u003c/code\u003e POST field against the \u003ccode\u003eon[A-Z][\\w+]*\u003c/code\u003e pattern before passing it to \u003ccode\u003erunAjaxHandler()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eUpdate \u003ccode\u003emodules/backend/controllers/Users.php\u003c/code\u003e to remove the conditional logic that sets \u003ccode\u003e$requiredPermissions\u003c/code\u003e to \u003ccode\u003enull\u003c/code\u003e for the \u003ccode\u003emyaccount\u003c/code\u003e action.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T16:49:07Z","date_published":"2026-08-12T16:49:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-winter-cms-bypass/","summary":"Authenticated backend users can exploit an input validation vulnerability in the Winter CMS form postback mechanism to execute restricted controller methods, leading to unauthorized administrative actions.","title":"Improper Input Validation in Winter CMS Backend Postback","url":"https://feed.craftedsignal.io/briefs/2026-08-winter-cms-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Wn-Backend-Module","version":"https://jsonfeed.org/version/1.1"}