THREAT OPS › Threat News › [GHSA] GHSA-hq84-x37p-j6q5 (medium) — Winter: Reflected XSS through the search query parameter in the backend Table widget
[GHSA] GHSA-hq84-x37p-j6q5 (medium) — Winter: Reflected XSS through the search query parameter in the backend Table widget
GHSA-hq84-x37p-j6q5 Severity: medium CVE: None
Winter: Reflected XSS through the search query parameter in the backend Table widget
### Impact
Affected versions of Winter CMS render the `search` query parameter without HTML encoding inside a `<script type="text/template">` block in the backend Table widget partial (`modules/backend/widgets/table/partials/_table.php`):
```php value="<?= get('se
Indicators of compromise
- 1b6397654124fb44a6abf6f3782b6a1d746cef14sha1
- hello@wintercms.comemail
Original source: https://github.com/advisories/GHSA-hq84-x37p-j6q5