TCMAN GIM Password Change Authorization Vulnerability

Vulnerability

An incorrect authorization vulnerability has been identified in TCMAN's GIM version 11. This vulnerability allows an attacker with low privileges to change the passwords of other users. The exploitation involves sending a POST request to '/PC/WebService.aspx/validateChangePasswordña' with the parameters 'idUser', 'PasswordActual', 'PasswordNew', and 'PasswordNewRepeat'. Notably, the 'PasswordActual' parameter must be left empty to successfully exploit this vulnerability.

Impact

Exploitation of this vulnerability allows for unauthorized password changes, potentially leading to account takeover.

Remediation

Users are advised to update to the latest version of TCMAN GIM Web, version 20250128, where this vulnerability has been fixed.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.