{"id":"GHSA-m7jc-g4rc-jmvh","summary":"Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax","details":"## Impact\n\nThe Backend Filter widget (`Backend\\Widgets\\Filter`) is vulnerable to SQL injection through the `numberrange` scope type when the scope is configured with a `conditions` key. An authenticated backend user with access to a list view containing a vulnerable filter scope can inject arbitrary SQL via the filter's AJAX handler, potentially gaining read access to the full database contents.\n\nTo exploit this, an attacker must have a valid backend account with access to a list view where a third-party plugin has registered a `numberrange` filter scope using the `conditions` configuration key. No built-in Winter CMS backend views use this scope type and configuration combination, so a vanilla installation without plugins is not exploitable.\n\n## Patches\n\nThis issue has been fixed in Winter CMS v1.2.13.\n\n## Workarounds\n\nIf users cannot upgrade, they may apply commit https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43 to your Winter CMS\ninstallation manually to resolve this issue.","aliases":["CVE-2026-32593"],"modified":"2026-08-12T14:56:06.567625Z","published":"2026-08-12T14:41:13Z","database_specific":{"cwe_ids":["CWE-89"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-08-12T14:41:13Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/wintercms/winter/security/advisories/GHSA-m7jc-g4rc-jmvh"},{"type":"WEB","url":"https://github.com/wintercms/winter/commit/50713de95adf5298536d93f4d999652525d36d43"},{"type":"PACKAGE","url":"https://github.com/wintercms/winter"}],"affected":[{"package":{"name":"winter/wn-backend-module","ecosystem":"Packagist","purl":"pkg:composer/winter/wn-backend-module"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.13"}]}],"versions":["v1.0.473","v1.0.474","v1.0.475","v1.1.10","v1.1.11","v1.1.2","v1.1.3","v1.1.4","v1.1.5","v1.1.6","v1.1.7","v1.1.8","v1.1.9","v1.2.0","v1.2.1","v1.2.10","v1.2.11","v1.2.12","v1.2.2","v1.2.3","v1.2.4","v1.2.5","v1.2.6","v1.2.7","v1.2.8","v1.2.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.2.12","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-m7jc-g4rc-jmvh/GHSA-m7jc-g4rc-jmvh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}