← Terug naar overzicht

Winter CMS versions prior to 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in the System\Twig\SecurityPolicy component. Authenticated backend users with template-editing permissions can bypass sandbox restrictions through method forwarding via Eloquent models and query builders. Exploitable methods include saveQuietly(), deleteQuietly(), increment(), decrement(), and newQuery(). Successful exploitation allows attackers to read and modify arbitrary database records, execute arbitrary SQL queries, and achieve remote code execution by injecting PHP code into template sections. The vulnerability represents an incomplete patch for a previously identified sandbox escape issue. A fix is available in Winter CMS version 1.2.13 and later.

Affected products

  • Winter CMS

Related CVE's

  • CVE-2026-79774

Categories

  • Database & Storage
  • Web Technologies
  • Zero-Day Vulnerabilities