Stored Cross-Site Scripting Vulnerability in Windu CMS
CVE-2025-59115
5.3MEDIUM
What is CVE-2025-59115?
Windu CMS has a security flaw in the login page that allows attackers to exploit stored cross-site scripting (XSS) vulnerabilities. This vulnerability arises from inadequate validation of user input, enabling malicious actors to inject arbitrary HTML and JavaScript code. When an administrator accesses the logs page, this injected content can be rendered and executed, potentially compromising sensitive information and administrative functionalities. Although Windu was notified of this issue, they have not provided details regarding vulnerable versions beyond the confirmed affected version 4.1. Other versions may also be at risk.
Affected Version(s)
Windu CMS 0 <= 4.1
