← Vulnerability feed

Vulnerability record · CVE-2021-4046 · published 11 February 2022

CVE-2021-4046: Tcman gim cross-site scripting vulnerability

Tcman · Gim

The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.

5.4 CVSS 3.1 Medium EPSS 0.44% · top 63.6% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-4046 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-36276Tcman gim sql injection vulnerabilityTCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerabilit…EPSS 0.78%9.8CVE-2021-40850Tcman gim sql injection vulnerabilityTCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.EPSS 0.94%9.3CVE-2025-40664Tcman gim missing authentication for critical function vulnerabilityMissing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, …EPSS 0.55%9.3CVE-2025-40624Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.44%9.3CVE-2025-40625Tcman gim unrestricted file upload vulnerabilityUnrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malic…EPSS 0.75%9.3CVE-2025-40623Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.44%9.3CVE-2025-40622Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.44%9.3CVE-2025-40621Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2021-4046), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.