CVE-2025-40670
09.06.2025, 13:15
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by sending a POST request to /PC/frmGestionUser.aspx/updateUser.Enginsight
| Vendor | Product | Version |
|---|---|---|
| tcman | gim | 11.0 |
𝑥
= Vulnerable software versions