CVE-2025-41015
02.12.2025, 14:16
User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable throughthe 'pda:username' parameter with 'soapaction GetUserQuestionAndAnswer' in '/WS/PDAWebService.asmx'.Enginsight
| Vendor | Product | Version |
|---|---|---|
| tcman | gim | 𝑥 < 2025-04-01 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration