CVE-2025-41346CRITICAL 9.8EPSS p23.6%
CVE-2025-41346CVE-2025-41346
Description
Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.31% probability of exploitation · percentile 23.6% · 2026-08-03T12:00:16Z |
| Published | 2025-11-18 |
| Last modified | 2025-11-19 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Incorrect Authorizationcwe-863 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.