Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1.
2025-06-09T13:15:22.803
2025-10-06T19:37:27.340
Analyzed
CVSSv3.1: 6.5 (MEDIUM)