The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.
| Software | From | Fixed in |
|---|---|---|
| tcman / gim | 8.0.1 | 8.0.1.x |
| tcman / gim | 8.01 | 8.01.x |