Vulnerabilities
24 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-41013 | SQL injection vulnerability in TCMAN GIM v11 in version 20250304. SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2025-40670 | Incorrect authorization vulnerability in TCMAN's GIM v11. Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by sending a POST request to /PC/frmGestionUser.aspx/updateUser. NVD description · AI analysis pending | 7.1 | <1% |
| — | ||
| CVE-2025-40664 | Missing authentication vulnerability in TCMAN GIM v11. Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, /frmGestionUser.aspx/updateUser and /frmGestionUser.aspx/DeleteUser. NVD description · AI analysis pending | 9.3 group max | <1% |
| — | ||
| CVE-2025-40625 | Unrestricted file upload in TCMAN's GIM v11. Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE). NVD description · AI analysis pending | 9.3 | <1% |
| — | ||
| CVE-2022-36276 +1 in the same advisory: …36277 | TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker to directly interact with the database. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2021-4046 | The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2021-40850 | TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx. TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx. NVD description · AI analysis pending | 9.8 group max | <1% |
| — |