CVE-2025-40669

MEDIUM

TCMAN GIM v11 - Unauthenticated Incorrect Authorization via POST Request to /PC/Options.aspx

Title source: llm
STIX 2.1

Description

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0021
EPSS Percentile 11.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
tcman/gim 11.0
Published Jun 09, 2025
Tracked Since Feb 18, 2026