Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt count or timeout is not stored on the server, which allows a malicious attacker to bypass this brute-force protection by resetting this parameter. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 4.1 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
History

Thu, 20 Nov 2025 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:windu:windu_cms:4.1:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Thu, 20 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Windu
Windu windu Cms
Vendors & Products Windu
Windu windu Cms

Tue, 18 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Nov 2025 14:30:00 +0000

Type Values Removed Values Added
Description Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt count or timeout is not stored on the server, which allows a malicious attacker to bypass this brute-force protection by resetting this parameter. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 4.1 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Title Bruteforce Protection Bypass in Windu CMS
Weaknesses CWE-307
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2025-11-18T13:26:31.504Z

Updated: 2025-11-18T17:13:06.755Z

Reserved: 2025-09-09T09:50:09.670Z

Link: CVE-2025-59113

cve-icon Vulnrichment

Updated: 2025-11-18T17:11:23.549Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-18T15:16:33.387

Modified: 2025-11-20T15:33:53.020

Link: CVE-2025-59113

cve-icon Redhat

No data.