← CVE Tracker
9.8CRITICAL

CVE-2025-41013 — SQL injection vulnerability in TCMAN GIM v11 in version 20250304.

Tcman · Gim · Published 2 Dec 2025 · Modified 25 Sept 2026

Description

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.

References

What to do
  1. Check whether Gim is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-41013