Stored Cross-Site Scripting (XSS) in WinPlus by Informática del Este
Vulnerability Description
Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41346
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Daniel Cano Merchán
More from Informatica del Este
View All →Affected Vendor
Informatica del Este
View all reports →