Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by the TCMAN team in the 20241112 release.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27978 | Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in /GIMWeb/PC/frmCorrectivosList.aspx. |
Fri, 10 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:tcman:gim:11.0:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 27 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 May 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in /GIMWeb/PC/frmCorrectivosList.aspx. | |
| Title | Time-based blind SQL injection vulnerability in TCMAN GIM v11 | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-27T14:23:12.934Z
Reserved: 2025-04-16T08:38:14.997Z
Link: CVE-2025-40665
Updated: 2025-05-27T14:23:10.714Z
Status : Analyzed
Published: 2025-05-26T13:15:20.300
Modified: 2025-10-10T20:14:57.310
Link: CVE-2025-40665
No data.
OpenCVE Enrichment
Updated: 2025-06-23T19:31:59Z
EUVD