TCMAN GIM Missing Authentication Vulnerability

Vulnerability

A missing authentication vulnerability exists in TCMAN GIM version 11, allowing unauthenticated attackers to access specific resources related to user management. The vulnerable endpoints include '/frmGestionUser.aspx/GetData', '/frmGestionUser.aspx/updateUser', and '/frmGestionUser.aspx/DeleteUser'.

Impact

Exploitation of this vulnerability allows unauthorized access to user management functionalities, potentially leading to unauthorized data manipulation or access.

Remediation

Users can upgrade to the TCMAN GIM version released on November 12, 2024, to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.