CVE-2025-59116
BaseFortify
Publication date: 2025-11-18
Last updated on: 2025-12-05
Assigner: CERT.PL
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| windu | windu_cms | 4.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-204 | The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Windu CMS allows an attacker to perform User Enumeration during the login process. The system reveals different messages depending on whether a login is valid or not, which enables an attacker to identify valid usernames and potentially carry out brute force attacks using those valid logins.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access attempts by allowing attackers to discover valid usernames. This increases the risk of brute force attacks on user accounts, potentially compromising user data and system security.