CVE-2025-41350: Iest Winplus
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'descripcion' parameter in '/WinplusPortal/ws/sWinplus.svc/json/savesoldoc_post'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.
Affected products
- Iest Winplus: version 24.11.27 only
Published 2025-11-18. Last modified 2026-06-17.