Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Informatica Del Este
Informatica Del Este winplus |
|
| Vendors & Products |
Informatica Del Este
Informatica Del Este winplus |
Tue, 18 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application. | |
| Title | Stored Cross-Site Scripting (XSS) in WinPlus by Informática del Este | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-11-18T21:12:26.877Z
Reserved: 2025-04-16T09:57:03.670Z
Link: CVE-2025-41346
Updated: 2025-11-18T21:12:23.383Z
Status : Awaiting Analysis
Published: 2025-11-18T10:15:49.847
Modified: 2025-11-18T14:06:29.817
Link: CVE-2025-41346
No data.