{"id":"GHSA-mpmw-f6h6-3g26","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mpmw-f6h6-3g26","summary":"Winter: My Account preview exposes another backend user's profile by record ID","details":"### Impact\n\n`Backend\\Controllers\\MyAccount`, introduced in v1.2.13, declares an empty `$requiredPermissions` array so that any authenticated backend user can manage their own account. It implements the `FormController` behavior, which exposes three routable actions — `create`, `update` and `preview` — that each take a record id from the URL.\n\n`index()` passes the authenticated user's own id to the behavior, but the inherited actions were left routable and `formFindModelObject()` was not scoped, so a caller-supplied id resolved against an unscoped `Backend\\Models\\User` query:\n\n```\nGET /backend/backend/myaccount/preview/{other_user_id}\n```\n\n`preview` disclosed the target user's first name, last name, login, email address and avatar; `update` was equally routable and additionally disclosed role, group membership, superuser flag and throttle state. Password controls render a mask, so no credential material was exposed. Backend user ids are sequential and trivially enumerated, and as these are `GET` actions no CSRF token is involved.\n\nThe behavior's AJAX handlers (`create_onSave`, `update_onSave`, `update_onDelete`) were also dispatchable on these routes, but cross-user writes were blocked by the `Backend\\Models\\User` authorization guards added in v1.2.13. The confirmed impact is unauthorized disclosure of backend user profile data.\n\nTo actively exploit this security issue, an attacker would need access to the Backend with a user account with any level of access.\n\n### Patches\n\n`MyAccount` no longer exposes the generic record actions it never used as routes, and its form lookup is now pinned to the authenticated user:\n\n- `protected $guarded = ['create', 'update', 'preview'];` removes the inherited actions from routing. The guard has to be at the routing layer, as handler dispatch (`{action}_{handler}`) runs before the page action.\n- `formExtendQuery()` constrains every lookup made by the behavior to the current user's key.\n\nThis security issue has been fixed as of **v1.2.14** (commit [`cdbc8f5a23db27f72ccec658a8e5769e6d9f6dcb`](https://github.com/wintercms/winter/commit/cdbc8f5a23db27f72ccec658a8e5769e6d9f6dcb)).\n\n### Workarounds\n\nThere is no supported workaround other than upgrading. If you cannot upgrade immediately, you may apply the fix manually in `modules/backend/controllers/MyAccount.php`:\n\n1. Add `protected $guarded = ['create', 'update', 'preview'];` to the controller.\n2. Add a `formExtendQuery()` method that scopes the lookup to the current user:\n\n```php\npublic function formExtendQuery(\\Winter\\Storm\\Database\\Builder $query): void\n{\n    $query->whereKey($this->user->getKey());\n}\n```\n\n### References\n\n- https://github.com/wintercms/winter/security/advisories/GHSA-j5jq-cr68-v2xx\n- https://github.com/wintercms/winter/commit/cdbc8f5a23db27f72ccec658a8e5769e6d9f6dcb\n\n\nCredit to Awwader ([@NRAwwad](https://github.com/NRAwwad)) for reporting the issue.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n- Email us at [hello@wintercms.com](mailto:hello@wintercms.com)","published":"2026-08-20T18:44:45Z","modified":"2026-08-20T19:00:08.482221998Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"winter/wn-backend-module","fixedVersion":"1.2.14"}],"fix":{"url":"https://github.com/wintercms/winter/commit/cdbc8f5a23db27f72ccec658a8e5769e6d9f6dcb","label":"wintercms/winter@cdbc8f5"},"references":[{"type":"WEB","url":"https://github.com/wintercms/winter/security/advisories/GHSA-mpmw-f6h6-3g26"},{"type":"WEB","url":"https://github.com/wintercms/winter/commit/cdbc8f5a23db27f72ccec658a8e5769e6d9f6dcb"},{"type":"PACKAGE","url":"https://github.com/wintercms/winter"},{"type":"WEB","url":"https://github.com/wintercms/winter/releases/tag/v1.2.14"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T19:00:08.482221998Z"}}