Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'descripcion' parameter in '/WinplusPortal/ws/sWinplus. svc/json/savesolpla_post'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-winplus-informatica-del-este | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-11-18 12:15
Updated : 2025-11-19 19:13
NVD link : CVE-2025-41349
Mitre link : CVE-2025-41349
CVE.ORG link : CVE-2025-41349
JSON object : View
Products Affected
iest
- winplus
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
