Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-winplus-informatica-del-este | Third Party Advisory |
Configurations
History
19 Nov 2025, 19:14
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Iest
Iest winplus |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-winplus-informatica-del-este - Third Party Advisory | |
| CPE | cpe:2.3:a:iest:winplus:24.11.27:*:*:*:-:*:*:* |
18 Nov 2025, 10:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-18 10:15
Updated : 2025-11-19 19:14
NVD link : CVE-2025-41346
Mitre link : CVE-2025-41346
CVE.ORG link : CVE-2025-41346
JSON object : View
Products Affected
iest
- winplus
CWE
CWE-863
Incorrect Authorization
