Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of other users through a POST request using the parameters idUser, PasswordActual, PasswordNew and PasswordNewRepeat in /PC/WebService.aspx/validateChangePassword%C3%B1a. To exploit the vulnerability the PasswordActual parameter must be empty.
History

Mon, 09 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 12:45:00 +0000

Type Values Removed Values Added
Description Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of other users through a POST request using the parameters idUser, PasswordActual, PasswordNew and PasswordNewRepeat in /PC/WebService.aspx/validateChangePassword%C3%B1a. To exploit the vulnerability the PasswordActual parameter must be empty.
Title Incorrect Authorization vulnerability in TCMAN GIM
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-06-09T12:25:59.654Z

Updated: 2025-06-09T13:03:21.122Z

Reserved: 2025-04-16T08:38:14.998Z

Link: CVE-2025-40668

cve-icon Vulnrichment

Updated: 2025-06-09T13:03:17.609Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-09T13:15:22.633

Modified: 2025-06-12T16:06:47.857

Link: CVE-2025-40668

cve-icon Redhat

No data.