Vulnerability Description
Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iest | Winplus | 24.11.27 |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xThird Party Advisory
FAQ
What is CVE-2025-41346?
CVE-2025-41346 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could co...
How severe is CVE-2025-41346?
CVE-2025-41346 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-41346?
Check the references section above for vendor advisories and patch information. Affected products include: Iest Winplus.