← Vulnerability feed

Vulnerability record · CVE-2025-40624 · published 6 May 2025

CVE-2025-40624: Tcman gim sql injection vulnerability

Tcman · Gim

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ and “email” parameters of the ‘updatePassword’ endpoint.

9.3 CVSS 4.0 Critical EPSS 0.42% · top 65.9% CWE-89 · SQL injection
9.3CVSS 4.0 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ and “email” parameters of the ‘updatePassword’ endpoint.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-40624 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-36276Tcman gim sql injection vulnerabilityTCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerabilit…EPSS 0.77%9.8CVE-2021-40850Tcman gim sql injection vulnerabilityTCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.EPSS 0.94%9.3CVE-2025-40664Tcman gim missing authentication for critical function vulnerabilityMissing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, …EPSS 0.55%9.3CVE-2025-40623Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40625Tcman gim unrestricted file upload vulnerabilityUnrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malic…EPSS 0.70%9.3CVE-2025-40621Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40622Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40620Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2025-40624), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.