{"id":63690,"date":"2025-05-26T17:31:53","date_gmt":"2025-05-26T14:01:53","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-40667-tcmans-gim-missing-authorization-vulnerability-authorization-bypass\/"},"modified":"2025-05-26T17:31:53","modified_gmt":"2025-05-26T14:01:53","slug":"cve-2025-40667-tcmans-gim-missing-authorization-vulnerability-authorization-bypass","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-40667-tcmans-gim-missing-authorization-vulnerability-authorization-bypass\/","title":{"rendered":"CVE-2025-40667 &#8211; TCMAN&#8217;s GIM Missing Authorization Vulnerability (Authorization Bypass)"},"content":{"rendered":"<p><strong>CVE ID : <\/strong>CVE-2025-40667<br \/>\n<br \/>\n<strong>Published : <\/strong> May 26, 2025, 1:15 p.m. | 15\u00a0minutes ago<br \/>\n<br \/>\n<strong>Description : <\/strong>Missing authorization vulnerability in TCMAN&#8217;s GIM v11. This allows an authenticated attacker to access any functionality of the application even when they are not available through the user interface. To exploit the vulnerability the attacker must modify the HTTP code of the response from \u2018302 Found\u2019 to \u2018200 OK\u2019, as well as the hidden fields hdnReadOnly and hdnUserLogin.<br \/>\n<br \/>\n<strong>Severity:<\/strong> 0.0 | NA<br \/>\n<br \/>\nVisit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-40667 Published : May 26, 2025, 1:15 p.m. | 15\u00a0minutes ago Description : Missing authorization vulnerability in TCMAN&#8217;s GIM v11. This allows an authenticated attacker to access any functionality of the application even when they are not available through the user interface. To exploit the vulnerability the attacker must modify the HTTP &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-63690","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/63690","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=63690"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/63690\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=63690"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=63690"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=63690"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}