Impact
A blind SQL injection flaw exists in Windu CMS that allows a remote attacker to insert SQL syntax into the URL path portion of an HTTP header. The vulnerability is exploitable without any authentication, meaning an attacker can access the underlying database and retrieve data.
Affected Systems
The issue has been confirmed in Windu CMS version 4.1; other releases may also be affected, but this is not yet verified.
Risk and Exploitability
The CVSS score of 9.3 classifies this as a critical flaw, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could use blind SQL injection to infer and exfiltrate sensitive data from the database by manipulating the HTTP header. No administrative privileges are required for the attack.
OpenCVE Enrichment