PT-2025-47309 · Windu Cms · Windu Cms
Karol Czubernat
·
Published
2025-11-18
·
Updated
2025-12-05
·
CVE-2025-59111
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Windu CMS version 4.1
Windu CMS (affected versions not specified)
Description
Windu CMS has a flaw related to access control in the user editing feature. An attacker with sufficient privileges can send a GET request to delete Super Admins, a function not normally accessible through the graphical user interface. The vendor was informed of this issue but did not provide details about vulnerable versions.
Recommendations
Apply any available updates or patches for Windu CMS version 4.1.
For other versions, implement strict access controls and regularly review user privileges.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windu Cms