WinPlus Authorization Bypass Vulnerability Allowing User Impersonation

Vulnerability

A vulnerability in WinPlus version 24.11.27 by Informática del Este allows for improper authorization control, enabling one user to impersonate another by simply knowing their numerical ID. This flaw could lead to unauthorized access to another user's account, potentially compromising the confidentiality, integrity, and availability of the data within the application.

Impact

Exploitation of this vulnerability could result in unauthorized account access, allowing an attacker to manipulate data and access resources intended for the impersonated user.

Added: Nov 18, 2025, 10:18 AM
Updated: Nov 18, 2025, 2:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.9
exploitability
6.2
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.