WinPlus Unlimited Dangerous File Upload Vulnerability
Vulnerability
A vulnerability allowing unlimited uploads of dangerous file types has been identified in WinPlus version 24.11.27 by Informática del Este. This issue enables attackers to upload 'webshells' by sending POST requests to the '/WinplusPortal/ws/sWinplus.svc/json/uploadfile' endpoint.
Impact
Exploitation of this vulnerability allows for the upload of malicious files, such as webshells, which could be executed on the server.
Added: Nov 18, 2025, 11:21 AM
Updated: Nov 18, 2025, 2:45 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
5.2remediation
0.0relevance
1.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
