CNNVD-202511-2083 Information

CNNVD ID

CNNVD-202511-2083

CVE-2025-41347

  • CNNVD Published: 2025-11-18

Description (Chinese)

Informática del Este WinPlus是西班牙Informática del Este公司的一个人力资源管理平台。 Informática del Este WinPlus v24.11.27版本存在代码问题漏洞,该漏洞源于危险文件类型上传无限制,可能导致攻击者上传webshell。

Description (English)

Informática del Este WinPlus is a human resources management platform of the Spanish company Informática del Este. Version Informática del Este WinPlus v. 24.11.27 contains a code gap that stems from the unrestricted uploading of dangerous document types, which may lead to the uploading of webshell by the attackers.

Hazard Level

High

Vulnerability Type

代码问题

Affected Vendor

Informática del Este

Published

2025-11-18

Last Modified

2026-02-24

References

https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-xss-winplus-informatica-del-este

Share on: