Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
There is no solution reported at this time.
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application. | |
| Title | Stored Cross-Site Scripting (XSS) in WinPlus by Informática del Este | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-11-18T10:04:11.741Z
Reserved: 2025-04-16T09:57:03.670Z
Link: CVE-2025-41346
No data.
Status : Received
Published: 2025-11-18T10:15:49.847
Modified: 2025-11-18T10:15:49.847
Link: CVE-2025-41346
No data.
OpenCVE Enrichment
No data.