PT-2026-61589 · Windu Cms · Windu Cms

·

CVE-2026-57311

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Windu CMS version 4.1
Description An authenticated attacker can upload arbitrary files, including PHP scripts, because the system does not validate the types of uploaded files. This flaw can lead to Remote Code Execution (RCE), which allows an attacker to execute arbitrary commands on the server. There have been reports of elevated activities targeting this software.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57311

Affected Products

Windu Cms