Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by the TCMAN team in the 20241112 release.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27979 | Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in/GIMWeb/PC/frmPreventivosList.aspx. |
Fri, 10 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:tcman:gim:11.0:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 27 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 May 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in/GIMWeb/PC/frmPreventivosList.aspx. | |
| Title | Time-based blind SQL injection vulnerability in TCMAN GIM v11 | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-27T14:13:29.073Z
Reserved: 2025-04-16T08:38:14.998Z
Link: CVE-2025-40666
Updated: 2025-05-27T14:13:26.196Z
Status : Analyzed
Published: 2025-05-26T13:15:20.440
Modified: 2025-10-10T20:14:48.750
Link: CVE-2025-40666
No data.
OpenCVE Enrichment
Updated: 2025-06-23T19:31:59Z
EUVD