Executive brief
Windu CMS, a platform used for building and managing websites, uses outdated and weak methods to protect user passwords. If an attacker gains access to the website's database, they can easily reverse the stored password information to reveal the actual plain-text passwords of users and administrators. This could lead to full account takeovers and unauthorized access to the website's management panel.
Technical details
Windu CMS (confirmed in version 4.1) implements insufficient computational effort for password storage by utilizing MD5 and SHA1 hashing algorithms combined with a static salt. This violates modern cryptographic standards which require slow, salted, and iterated hashing functions like Argon2 or bcrypt. If an attacker obtains the password hashes (e.g., via a separate SQL injection vulnerability), the use of weak algorithms and a non-unique salt allows for rapid offline brute-force or rainbow table attacks to recover cleartext credentials. No patch is currently available as vendor contact attempts were unsuccessful.
Affected products
- JCD Windu CMS 4.1
Timeline
- 2026-07-20: advisory: Advisory published by CERT.PL