Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13582 | SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ parameter of the ‘ValidateUserAndWS’ endpoint. |
Solution
The vulnerability has been fixed by the TCMAN team in version 1280.
Workaround
No workaround given by the vendor.
Sun, 13 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 14 May 2025 04:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tcman
Tcman gim |
|
| CPEs | cpe:2.3:a:tcman:gim:11.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Tcman
Tcman gim |
|
| Metrics |
cvssV3_1
|
Wed, 07 May 2025 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 May 2025 20:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ parameter of the ‘ValidateUserAndWS’ endpoint. | |
| Title | Multiple vulnerabilities in TCMAN's GIM | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-06T15:10:34.244Z
Reserved: 2025-04-16T08:38:07.129Z
Link: CVE-2025-40620
Updated: 2025-05-06T15:10:28.593Z
Status : Analyzed
Published: 2025-05-06T11:15:50.850
Modified: 2025-05-13T19:07:03.610
Link: CVE-2025-40620
No data.
OpenCVE Enrichment
No data.
EUVD