9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.
AI Analysis
Stored Cross-Site Scripting (XSS) vulnerability in WinPlus by Informática del Este due to faulty authorization control, allowing an attacker to impersonate users and compromise data confidentiality, integrity, and availability.
Basic Information
ID
CVE-2025-41346
Source
INCIBE
Published
Nov 18, 2025 at 10:04
Affected Product
Vendor
Informática del Este
Product
WinPlus
Version
24.11.27
Affected Versions
Informática del Este WinPlus 24.11.27
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Informática del Este
Product
WinPlus
Version
24.11.27