PT-2025-47313 · Windu Cms · Windu Cms
Karol Czubernat
·
Published
2025-11-18
·
Updated
2025-12-05
·
CVE-2025-59115
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Windu CMS version 4.1
Windu CMS (affected versions not specified)
Description
Windu CMS is susceptible to Stored Cross-Site Scripting (XSS) in the logon page due to inadequate input validation. A malicious actor can inject arbitrary HTML and JavaScript code into the website. This injected code will be rendered and executed when an administrator visits the logs page.
Recommendations
Apply appropriate input validation to all user-supplied data on the logon page.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windu Cms