Beveiligingsadvies

CVE-2025-40669

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-06-09 12:26:11
Laatst bijgewerkt 2025-06-09 13:02:46
Toegewezen door INCIBE
CVSS-score 7.1
Status PUBLISHED

Beschrijving

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1.