Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13580 | SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘username’ parameter of the ‘GetLastDatePasswordChange’ endpoint. |
Solution
The vulnerability has been fixed by the TCMAN team in version 1280.
Workaround
No workaround given by the vendor.
Sun, 13 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 14 May 2025 04:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tcman
Tcman gim |
|
| CPEs | cpe:2.3:a:tcman:gim:11.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Tcman
Tcman gim |
|
| Metrics |
cvssV3_1
|
Wed, 07 May 2025 01:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 May 2025 20:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘username’ parameter of the ‘GetLastDatePasswordChange’ endpoint. | |
| Title | Multiple vulnerabilities in TCMAN's GIM | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-06T15:08:27.737Z
Reserved: 2025-04-16T08:38:07.129Z
Link: CVE-2025-40622
Updated: 2025-05-06T15:08:20.764Z
Status : Analyzed
Published: 2025-05-06T11:15:51.917
Modified: 2025-05-13T19:07:51.707
Link: CVE-2025-40622
No data.
OpenCVE Enrichment
No data.
EUVD