CVE 9.3 CRITICAL

Stored Cross-Site Scripting (XSS) in WinPlus by Informática del Este_CVE-2025-41346

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.

AI Analysis

Stored Cross-Site Scripting (XSS) vulnerability in WinPlus by Informática del Este due to faulty authorization control, allowing an attacker to impersonate users and compromise data confidentiality, integrity, and availability.

Basic Information

ID CVE-2025-41346
Source INCIBE
Published Nov 18, 2025 at 10:04

Affected Product

Vendor Informática del Este
Product WinPlus
Version 24.11.27
Affected Versions Informática del Este WinPlus 24.11.27

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Informática del Este
Product WinPlus
Version 24.11.27

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.