PT-2025-48680 · Tcman Gim · Tcman Gim

CVE-2025-41012

·

Publicado

2025-12-02

·

Atualizado

2025-12-03

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TCMAN GIM version 20250304
Description An unauthenticated attacker can determine if a user exists on the system. This is achieved by utilizing the pda:userId and pda:newPassword parameters with the 'soapaction UnlockUser’ within the '/WS/PDAWebService.asmx' endpoint.
Recommendations Apply restrictions to the '/WS/PDAWebService.asmx' API endpoint. Avoid using the pda:userId and pda:newPassword parameters.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-41012

Produtos afetados

Tcman Gim