{"id":"CVE-2026-32593","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-32593","summary":"Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax","details":"## Impact\n\nThe Backend Filter widget (`Backend\\Widgets\\Filter`) is vulnerable to SQL injection through the `numberrange` scope type when the scope is configured with a `conditions` key. An authenticated backend user with access to a list view containing a vulnerable filter scope can inject arbitrary SQL via the filter's AJAX handler, potentially gaining read access to the full database contents.\n\nTo exploit this, an attacker must have a valid backend account with access to a list view where a third-party plugin has registered a `numberrange` filter scope using the `conditions` configuration key. No built-in Winter CMS backend views use this scope type and configuration combination, so a vanilla installation without plugins is not exploitable.\n\n## Patches\n\nThis issue has been fixed in Winter CMS v1.2.13.\n\n## Workarounds\n\nIf users cannot upgrade, they may apply commit https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43 to your Winter CMS\ninstallation manually to resolve this issue.","published":"2026-08-12T14:41:13Z","modified":"2026-08-12T14:45:07.178703883Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"winter/wn-backend-module","fixedVersion":"1.2.13"}],"fix":{"url":"https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43","label":"wintercms/winter@50713de"},"references":[{"type":"WEB","url":"https://github.com/wintercms/winter/security/advisories/GHSA-m7jc-g4rc-jmvh"},{"type":"WEB","url":"https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43"},{"type":"PACKAGE","url":"https://github.com/wintercms/winter"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T14:45:07.178703883Z"}}