Windu CMS Vulnerable to Cross-Site Request Forgery in User Editing Functionality
CVE-2025-59110
What is CVE-2025-59110?
Windu CMS has a security flaw that allows attackers to exploit the Cross-Site Request Forgery vulnerability in its user editing functionality. This issue arises because the CSRF protection mechanism can be bypassed by using a CSRF token from another user, leading to unauthorized actions. As registration is open to anyone, an attacker could potentially create an account and perform malicious activities without the victim’s consent. Although testing confirmed version 4.1 is vulnerable, the vendor has not provided a detailed response regarding other potential affected versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Windu CMS 0 <= 4.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
