CVE-2025-59113 Details
Description
Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt count or timeout is not stored on the server, which allows a malicious attacker to bypass this brute-force protection by resetting this parameter. Only version 4.1 was tested and confirmed as vulnerable. This issue was fixed in version 4.1 build 2250.
A vulnerability exists in Windu CMS version 4.1, allowing attackers to bypass weak client-side brute-force protection. The application uses the 'loginError' parameter to manage login attempts, but does not store attempt counts or timeout information on the server. This lack of server-side tracking enables attackers to reset the 'loginError' parameter and circumvent brute-force defenses. While the vendor was notified of this vulnerability, no response regarding the details or affected version range was received. Only version 4.1 has been tested and confirmed vulnerable, leaving the status of other versions uncertain.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2025/11/CVE-2025-59110 | [email protected] | Third Party Advisory |
| https://windu.org | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| windu windu cms | 4.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 5, 2025 | CVE Modified | [email protected] |
| Nov 20, 2025 | Initial Analysis | [email protected] |
| Nov 18, 2025 | New CVE Received | [email protected] |