CVE-2025-41346

CRITICAL

WinPlus 24.11.27 - Incorrect Authorization via Numerical ID Impersonation

Title source: llm
STIX 2.1

Description

Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.

Scores

CVSS v3 9.8
EPSS 0.0028
EPSS Percentile 19.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
iest/winplus 24.11.27
Published Nov 18, 2025
Tracked Since Feb 18, 2026