S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Feb 18, 2024

CVE-2023-52085 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in Winter CMS affects v. before 1.2.4.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-52085
3.3
CVSSlow
Exploitable remotely over the internet · requires high privileges.

Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the compilation of custom stylesheets via LESS. This had the potential to lead to a Local File Inclusion vulnerability. This issue has been patched in v1.2.4.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
winterby wintercms
< 1.2.4
Updated Aug 19, 2026View on NVD →
Detail

Vulnerability Overview

Winter CMS before version 1.2.4 suffers from a Local File Inclusion vulnerability due to unvalidated input in ColorPicker FormWidget, allowing attackers with backend access to include local files, potentially leading to sensitive information disclosure.

Vulnerability Details

Attackers exploit this vulnerability by manipulating the ColorPicker FormWidget's input, leading to the inclusion of arbitrary files present on the server. This flaw specifically impacts the custom stylesheets compilation process via LESS, opening a path for LFI attacks.

Possible Effects

  • Information Disclosure: Access to sensitive files like /etc/passwd.
  • Unauthorized Access: Potential pathway to more severe exploitation vectors.

Why Choose S4E

At S4E, we offer cutting-edge scanning solutions designed to identify and address vulnerabilities like CVE-2023-52085 efficiently. By choosing us, you benefit from:

  • Comprehensive vulnerability assessments tailored to your needs.
  • Detailed reports and actionable remediation guidance.
  • Continuous support from our team of cybersecurity experts. Enhance your cyber resilience with S4E, ensuring your digital assets remain secure against evolving threats.

References

Solution Advice
  • Update Winter CMS: Upgrade to version 1.2.4 or later to apply the security patch.
  • Review User Permissions: Limit backend access to trusted users.
  • Monitor for Anomalies: Regularly scan and monitor for unusual backend activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.