Tcman Gim · Tcman Gim · CVE-2025-40664
**Name of the Vulnerable Software and Affected Versions**
TCMAN GIM version 11
**Description**
A missing authentication vulnerability in TCMAN GIM version 11 allows an unauthenticated attacker to access resources such as /frmGestionUser.aspx/GetData, /frmGestionUser.aspx/updateUser, and /frmGestionUser.aspx/DeleteUser. This enables the attacker to access and modify user data.
**Recommendations**
For TCMAN GIM version 11, as a temporary workaround, consider disabling access to the `/frmGestionUser.aspx/GetData`, `/frmGestionUser.aspx/updateUser`, and `/frmGestionUser.aspx/DeleteUser` endpoints until a patch is available. Restrict access to the user management functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.