Windu CMS Vulnerable to Cross-Site Request Forgery in User Editing Functionality
CVE-2025-59110

6.8MEDIUM

Key Information:

Vendor

Jcd

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-59110?

Windu CMS has a security flaw that allows attackers to exploit the Cross-Site Request Forgery vulnerability in its user editing functionality. This issue arises because the CSRF protection mechanism can be bypassed by using a CSRF token from another user, leading to unauthorized actions. As registration is open to anyone, an attacker could potentially create an account and perform malicious activities without the victim’s consent. Although testing confirmed version 4.1 is vulnerable, the vendor has not provided a detailed response regarding other potential affected versions.

Affected Version(s)

Windu CMS 4.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karol Czubernat
.
CVE-2025-59110 : Windu CMS Vulnerable to Cross-Site Request Forgery in User Editing Functionality