THREAT OPS › Threat News › [GHSA] GHSA-m7jc-g4rc-jmvh (medium) — Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax
[GHSA] GHSA-m7jc-g4rc-jmvh (medium) — Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax
GHSA-m7jc-g4rc-jmvh Severity: medium CVE: CVE-2026-32593
Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax
## Impact
The Backend Filter widget (`Backend\Widgets\Filter`) is vulnerable to SQL injection through the `numberrange` scope type when the scope is configured with a `conditions` key. An authenticated backend user with access to a list view containing a
Indicators of compromise
- 50713de95adf5298536d93f4d999652525d36d43sha1
- CVE-2026-32593cve
Original source: https://github.com/advisories/GHSA-m7jc-g4rc-jmvh