TCMAN GIM
cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*
- 11
An incorrect authorization vulnerability has been identified in TCMAN's GIM version 11. This vulnerability allows an attacker with low privileges to change the passwords of other users. The exploitation involves sending a POST request to '/PC/WebService.aspx/validateChangePasswordña' with the parameters 'idUser', 'PasswordActual', 'PasswordNew', and 'PasswordNewRepeat'. Notably, the 'PasswordActual' parameter must be left empty to successfully exploit this vulnerability.
Exploitation of this vulnerability allows for unauthorized password changes, potentially leading to account takeover.
Users are advised to update to the latest version of TCMAN GIM Web, version 20250128, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.