Windu CMS Vulnerable to Cross-Site Request Forgery in User Editing Functionality
CVE-2025-59110
6.8MEDIUM
What is CVE-2025-59110?
Windu CMS has a security flaw that allows attackers to exploit the Cross-Site Request Forgery vulnerability in its user editing functionality. This issue arises because the CSRF protection mechanism can be bypassed by using a CSRF token from another user, leading to unauthorized actions. As registration is open to anyone, an attacker could potentially create an account and perform malicious activities without the victim’s consent. Although testing confirmed version 4.1 is vulnerable, the vendor has not provided a detailed response regarding other potential affected versions.
Affected Version(s)
Windu CMS 4.1
