Impact
A blind SQL injection flaw exists in Windu CMS, allowing a remote attacker to inject SQL syntax through the URL path contained in an HTTP header; the flaw is exploited without requiring authentication, enabling the attacker to retrieve data from the underlying database.
Affected Systems
The vulnerability is confirmed in Windu CMS version 4.1, and other releases may also be affected.
Risk and Exploitability
The CVSS score of 9.3 marks this as a critical flaw. Because the EPSS score is not available, the exact likelihood of exploitation is unclear, but the absence of a KEV listing does not diminish the potential impact. Attackers can deliver a crafted HTTP request directly to the vulnerable server and use the blind nature of the injection to infer database information through time‑based or error‑based techniques. No special user privileges are required, so the attack surface is wide.
OpenCVE Enrichment