# Hacking into Toyota's global supplier management network

DevFeed: [Hacking into Toyota's global supplier management network](<https://devfeed.tech/articles/hacking-into-toyota-s-global-supplier-management-network-32602.md>)

Original publisher: [Read original article](<https://eaton-works.com/2023/02/06/toyota-gspims-hack/>)

Author: Eaton

Published: 2023-02-06T16:22:56Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Web app](<https://devfeed.tech/topics/webapp.md>), [account](<https://devfeed.tech/topics/account.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [data](<https://devfeed.tech/tags/data.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

## AI overview

A security researcher describes exploiting Toyota's Global Supplier Preparation Information Management System (GSPIMS), a web application used by Toyota employees and suppliers. An accidentally introduced backdoor in an impersonation feature enabled login as users, including administrators, using only their email addresses. The researcher reported the issue to Toyota in November 2022, and Toyota fixed it in a timely manner.

## Source excerpt

Inside an exploit that allowed logging in to Toyota's GSPIMS application as any user, including system admins.