Vulnerabilities > Windu

DATE CVE VULNERABILITY TITLE RISK
2019-08-01 CVE-2013-7474 Cross-site Scripting vulnerability in Windu CMS 2.2
Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.
network
low complexity
windu CWE-79
6.1
2019-08-01 CVE-2013-7473 Cross-Site Request Forgery (CSRF) vulnerability in Windu CMS 2.2
Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
network
low complexity
windu CWE-352
8.8