CVE-2025-41346

F

aulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.

Configurations

Configuration 1 (hide)

cpe:2.3:a:iest:winplus:24.11.27:*:*:*:-:*:*:*

History

19 Nov 2025, 19:14

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:iest:winplus:24.11.27:*:*:*:-:*:*:*
References () https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-winplus-informatica-del-este - () https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-winplus-informatica-del-este - Third Party Advisory
First Time Iest winplus
Iest

18 Nov 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-18 10:15

Updated : 2025-11-19 19:14


NVD link : CVE-2025-41346

Mitre link : CVE-2025-41346

CVE.ORG link : CVE-2025-41346


JSON object : View

Products Affected
CWE
CWE-863

Incorrect Authorization