Unlimited Upload Vulnerability in WinPlus by Informática del Este
CVE-2025-41347

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-41347?

An unlimited upload vulnerability exists in WinPlus version 24.11.27 developed by Informática del Este. This flaw allows attackers to upload harmful file types, such as webshells, by sending a specially crafted POST request to the '/WinplusPortal/ws/sWinplus.svc/json/uploadfile' endpoint. This issue risks unauthorized access and control over the affected system, making it imperative for users to mitigate the threat promptly.

Affected Version(s)

WinPlus 24.11.27

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Antonio Moreno GĂłmez
.
CVE-2025-41347 : Unlimited Upload Vulnerability in WinPlus by Informática del Este