CVE-2026-57309 PUBLISHED

Blind SQL Injection in Windu CMS

Assigner: CERT-PL
Reserved: 24.06.2026 Published: 20.07.2026 Updated: 20.07.2026

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection.

Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor JCD
Product Windu CMS
Versions Default: unknown
  • Version 4.1 is affected

Credits

  • Jakub Lipiński finder
  • Marek Tołczyk finder
  • Kamil Królikowski finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE

Impacts

  • CAPEC-7 Blind SQL Injection