TCMAN GIM Incorrect Authorization Vulnerability Allowing User Creation and Privilege Assignment

Vulnerability

An incorrect authorization vulnerability has been identified in TCMAN's GIM version 11. This vulnerability allows an unprivileged attacker to create a user and assign various privileges by sending a POST request to the 'frmGestionUser.aspx/updateUser' endpoint.

Impact

Exploitation of this vulnerability allows for unauthorized user creation and privilege assignment, potentially leading to elevated access rights within the application.

Remediation

The vulnerabilities have been fixed in the latest version of GIM Web, version 20250128.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
3.3
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.