CVE Database
/

CVE-2025-41347

Back to search

CVE-2025-41347

Published: Nov 18, 2025

Modified: Feb 18, 2026

PUBLISHED

Description

Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to upload a 'webshell' by sending a POST request to '/WinplusPortal/ws/sWinplus.svc/json/uploadfile'.

VendorProductVersions

Informatica del Este

WinPlus

affected
24.11.27

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now