Missing authorization vulnerability in TCMAN GIM v11
Vulnerability Description
Missing authorization vulnerability in TCMAN's GIM v11. This allows an authenticated attacker to access any functionality of the application even when they are not available through the user interface. To exploit the vulnerability the attacker must modify the HTTP code of the response from ‘302 Found’ to ‘200 OK’, as well as the hidden fields hdnReadOnly and hdnUserLogin.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-40667
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Carlos Aguadé
More from TCMAN
View All →Affected Vendor
TCMAN
View all reports →