User Enumeration Vulnerability in Windu CMS
CVE-2025-59116
6.9MEDIUM
What is CVE-2025-59116?
Windu CMS has a security flaw that allows user enumeration during the login process. By providing subtle differences in feedback messages, attackers can ascertain whether a username exists within the system. This vulnerability poses a risk of brute force attacks, as it may give malicious actors the ability to identify valid usernames and target them for unauthorized access. The vendor was informed but has not disclosed the full range of affected versions, although version 4.1 has been confirmed to be vulnerable.
Affected Version(s)
Windu CMS 4.1
