Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-41013


SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.


Published

2025-12-02T14:16:24.437

Last Modified

2025-12-03T19:54:41.300

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tcman gim < 2025-04-01 Yes

References