216.73.216.36

CVE-2025-41346

· Published 18/11/2025 10:15 · Modified 19/11/2025 19:14

Labels: CVE-2025-41346 2025-11-18CVE-2025-41346CWE-863[email protected]

Essential information

Published
18/11/2025 10:15
Modified
19/11/2025 19:14
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
iest / winplus cpe:2.3:a:iest:winplus:24.11.27:*:*:*:-:*:*:*

References