CVE-2025-41347
Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to upload a ‘webshell’ by sending a POST request to ‘/WinplusPortal/ws/sWinplus.svc/json/uploadfile’.
More information : https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-winplus-informatica-del-este
