SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
The vulnerabilitiy has been fixed by the TCMAN team in version 20250401.
Workaround
No workaround given by the vendor.
References
History
Tue, 02 Dec 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'. | |
| Title | SQL injection vulnerability in TCMAN GIM | |
| First Time appeared |
Tcman
Tcman gim |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tcman
Tcman gim |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-12-02T14:22:40.733Z
Reserved: 2025-04-16T09:08:43.218Z
Link: CVE-2025-41013
No data.
Status : Received
Published: 2025-12-02T14:16:24.437
Modified: 2025-12-02T14:16:24.437
Link: CVE-2025-41013
No data.
OpenCVE Enrichment
No data.