THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p2ch-c2c3-4xm5 (medium) — Winter: CSRF through AJAX handler names reachable as backend page actions

[GHSA] GHSA-p2ch-c2c3-4xm5 (medium) — Winter: CSRF through AJAX handler names reachable as backend page actions

highgithub_advisoriesPublished 2026-08-20

GHSA-p2ch-c2c3-4xm5 Severity: medium CVE: None

Winter: CSRF through AJAX handler names reachable as backend page actions

### Impact

Affected versions of Winter CMS allow a backend AJAX handler to be invoked by a plain top-level `GET` navigation with no CSRF token. `Backend\Classes\Controller::actionExists()` accepted any public method on a controller as a page action, so handler-shaped names we

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p2ch-c2c3-4xm5