THREAT OPS › Threat News › [GHSA] GHSA-7mpf-4465-7fc2 (low) — Winter: Stored XSS through Backend List widget image columns
[GHSA] GHSA-7mpf-4465-7fc2 (low) — Winter: Stored XSS through Backend List widget image columns
GHSA-7mpf-4465-7fc2 Severity: low CVE: None
Winter: Stored XSS through Backend List widget image columns
### Impact
`Backend\Widgets\Lists::evalImageTypeValue()` interpolated the resolved image URL into a single-quoted `src` attribute without escaping it. Where a list column of type `image` rendered an attacker-influenced value, that v
Indicators of compromise
- 0941c9816181095fe35d58e78e6d0c4a49238967sha1
- https://wintercms.com/docs/v1.2/docs/backend/lists#imageurl
- https://wintercms.com/docs/v1.2/docs/services/image-resizing#available-sourcesurl
- hello@wintercms.comemail
Original source: https://github.com/advisories/GHSA-7mpf-4465-7fc2