← Vulnerability feed

Vulnerability record · CVE-2022-36276 · published 4 October 2023

CVE-2022-36276: Tcman gim sql injection vulnerability

Tcman · Gim

TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker to directly interact with the database.

9.8 CVSS 3.1 Critical EPSS 0.77% · top 46.3% CWE-89 · SQL injection
9.8CVSS 3.1 base score
0.77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker to directly interact with the database.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36276 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-40850Tcman gim sql injection vulnerabilityTCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.EPSS 0.94%9.3CVE-2025-40664Tcman gim missing authentication for critical function vulnerabilityMissing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, …EPSS 0.55%9.3CVE-2025-40623Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40624Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40625Tcman gim unrestricted file upload vulnerabilityUnrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malic…EPSS 0.70%9.3CVE-2025-40621Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40622Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40620Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2022-36276), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.