In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade winter/wn-backend-module to version 1.2.13 or higher.
Affected versions of this package are vulnerable to SQL Injection in the numberrange scope of the backend filter widget when the conditions key is configured. An attacker can access sensitive database information by injecting arbitrary SQL through the filter's AJAX handler. This is only exploitable if an authenticated backend user has access to a list view where a third-party plugin has registered a numberrange filter scope using the conditions configuration key; default installations without such plugins are not affected.
This vulnerability can be mitigated by manually applying the patch from commit 50713de95adf5298536d93f4d999652525d36d43.