PT-2025-47308 · Windu Cms · Windu Cms
Karol Czubernat
·
Published
2025-11-18
·
Updated
2025-12-05
·
CVE-2025-59110
CVSS v4.0
6.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Windu CMS version 4.1
Windu CMS (affected versions not specified)
Description
Windu CMS has a flaw that allows attackers to perform Cross-Site Request Forgery (CSRF) attacks in the user editing functionality. The existing CSRF protection can be circumvented by utilizing the CSRF token from another user. Registration is open to anyone, allowing for easy account creation.
Recommendations
Apply a fix for Windu CMS version 4.1.
Implement a robust CSRF protection mechanism that prevents the use of CSRF tokens from other users.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windu Cms