VYPR

GIM

by TCMAN

CVEs (24)

  • CVE-2022-36277MedOct 4, 2023
    risk 0.42cvss 6.5epss 0.00

    The 'sReferencia', 'sDescripcion', 'txtCodigo' and 'txtDescripcion' parameters, in the frmGestionStock.aspx and frmEditServicio.aspx files in TCMAN GIM v8.0.1, could allow an attacker to perform persistent XSS attacks.

  • CVE-2021-40852MedDec 17, 2021
    risk 0.40cvss 6.1epss 0.01

    TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.

  • CVE-2021-4046MedFeb 11, 2022
    risk 0.35cvss 5.4epss 0.00

    The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.

  • CVE-2025-41012MedDec 2, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system by using the 'pda:userId' and 'pda:newPassword' parameters with 'soapaction UnlockUser’ in…

Page 2 of 2