mediumCVSS 4.5Vulnerability

GHSA-hq84-x37p-j6q5

### Impact Affected versions of Winter CMS render the `search` query parameter without HTML encoding inside a `<script type="text/template">` block in the backend Table widget partial (`modules/backend/widgets/table/partials/_table.php`): ```php value="<?= get('search') ?>" ``` `<script>` is an HTML raw-text context, so the surrounding `value="…"` attribute quoting is not a parser boundary. A literal `</script>` in the query string terminates the template element early, and everything after it is parsed as ordinary markup in the backend document. Any backend page rendering a Table or DataTable widget is a sink. The value is read from the global request through the `get()` helper, which — unlike `post()` — is not restricted by HTTP method, so a plain top-level `GET` navigation is sufficient. The template is also emitted unconditionally by the partial, so widgets using the default `searching: false` configuration are equally affected. In Winter core the reachable route is the **Editor Settings** form (`/backend/system/settings/update/winter/backend/editor`), which renders six `datatable` fields and is gated by `backend.manage_editor` — assigned by default to the built-in Developer role. Third-party plugins using the `datatable` form widget, or the Table widget directly, expose the same sink on their own pages. An attacker who induces a signed-in backend user to follow a crafted link executes script in that user's authenticated backend origin. The injected script can read the CSRF token published in the backend layout's `<meta name="csrf-token">` element and issue credentialed requests as the victim, bounded only by that user's permissions. Because the core sink requires `backend.manage_editor`, the practical victim is a Developer-role user or superuser — who can edit CMS templates, so script running in that session can chain to server-side code execution. This is not a permission bypass: the victim must already be authorised for the page, and the attacker gains

Properties

ghsa_id
GHSA-hq84-x37p-j6q5
severity
medium
summary
Winter: Reflected XSS through the search query parameter in the backend Table widget
cvss_score
4.5
cve_id
GHSA-hq84-x37p-j6q5
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-08-20T18:45:04Z
source_url
https://github.com/advisories/GHSA-hq84-x37p-j6q5
ghsa_updated
2026-08-20T18:45:05Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]composer/winter/wn-backend-module

AFFECTS (1)

[Software]composer/winter/wn-backend-module

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-hq84-x37p-j6q5 (CVSS 4.5) — Ninja Signal Threat Intelligence | Ninja Signal