← Vulnerability feed

Vulnerability record · CVE-2025-41013 · published 2 December 2025

CVE-2025-41013: Tcman gim sql injection vulnerability

Tcman · Gim

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.

8.7 CVSS 4.0 High EPSS 0.29% · top 81.0% CWE-89 · SQL injection
8.7CVSS 4.0 base score
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
25 Sep 2026Last modified by NVD

Description

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-41013 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-36276Tcman gim sql injection vulnerabilityTCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerabilit…EPSS 0.77%9.8CVE-2021-40850Tcman gim sql injection vulnerabilityTCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.EPSS 0.94%9.3CVE-2025-40664Tcman gim missing authentication for critical function vulnerabilityMissing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, …EPSS 0.55%9.3CVE-2025-40623Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40624Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40625Tcman gim unrestricted file upload vulnerabilityUnrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malic…EPSS 0.70%9.3CVE-2025-40621Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%9.3CVE-2025-40622Tcman gim sql injection vulnerabilitySQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all i…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2025-41013), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.