Incorrect Authorization Affecting winter/wn-backend-module package, versions <1.2.14


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-WINTERWNBACKENDMODULE-19428284
  • published29 Aug 2026
  • disclosed20 Aug 2026
  • creditUnknown

Introduced: 20 Aug 2026

New CVE NOT AVAILABLE CWE-862  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade winter/wn-backend-module to version 1.2.14 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Authorization in the ImportExportController AJAX handlers due to insufficient enforcement of granular access control. An attacker can access or modify sensitive data by invoking import or export operations through AJAX handlers without possessing the required granular permissions. This is only exploitable if the attacker has an authenticated backend account with access to a controller that implements this behavior and declares an import or export permission value more restrictive than the controller's own required permissions.

Workaround

This vulnerability can be mitigated by manually applying the permission check in each affected handler or by expressing the restriction in the controller's own required permissions property.

CVSS Base Scores

version 4.0
version 3.1