Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-54149

8.4 · HIGH
Published Dec 9, 2024 wintercms CWE-184 EPSS 0.40% (34th pctl)

Overview

CVE-2024-54149 is a high-severity vulnerability affecting wintercms winter. It was published on December 9, 2024 and has a CVSS 3.1 base score of 8.4 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.4, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

Technical Description

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow users with access to the CMS templates sections that modify Twig files to bypass the sandbox placed on Twig files and modify resources such as theme customisation values or modify, or remove, templates in the theme even if not provided direct access via the permissions. As all objects passed through to Twig are references to the live objects, it is also possible to also manipulate model data if models are passed directly to Twig, including changing attributes or even removing records entirely. In most cases, this is unwanted behavior and potentially dangerous. To actively exploit this security issue, an attacker would need access to the Backend with a user account with any of the following permissions: `cms.manage_layouts`; `cms.manage_pages`; or `cms.manage_partials`. The Winter CMS maintainers strongly recommend that these per

Remediation

Check the references section for vendor advisories and patches from wintercms. Update winter to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
wintercms winter >= 0, < 1.0.476 Affected

Frequently Asked Questions

What is CVE-2024-54149?

CVE-2024-54149 is a high-severity vulnerability affecting wintercms winter. It was published on December 9, 2024 and has a CVSS 3.1 base score of 8.4 (HIGH).

How severe is CVE-2024-54149?

This vulnerability has a CVSS 3.1 base score of 8.4, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2024-54149?

Check the references section for vendor advisories and patches from wintercms. Update winter to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-54149?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-54149 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.