Home/Product/tcman gim
Product

tcman gim

24 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-41015
< 2025-04-01
User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determi
7.5HIGH
CVE-2025-41014
< 2025-04-01
User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determi
7.5HIGH
CVE-2025-41013
< 2025-04-01
SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, updat
9.8CRITICAL
CVE-2025-41012
< 2025-04-01
Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to dete
5.3MEDIUM
CVE-2025-40670
all versions
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and
8.8HIGH
CVE-2025-40669
all versions
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permiss
6.5MEDIUM
CVE-2025-40668
all versions
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to chan
6.5MEDIUM
CVE-2025-40667
all versions
Missing authorization vulnerability in TCMAN's GIM v11. This allows an authenticated attacker to access any functionality of the a
6.5MEDIUM
CVE-2025-40666
all versions
Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete
9.8CRITICAL
CVE-2025-40665
all versions
Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete
9.8CRITICAL
CVE-2025-40664
all versions
Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestion
9.1CRITICAL
CVE-2025-40625
all versions
Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the s
9.8CRITICAL
CVE-2025-40624
all versions
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, upda
9.8CRITICAL
CVE-2025-40623
all versions
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, upda
9.8CRITICAL
CVE-2025-40622
all versions
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, upda
9.8CRITICAL
CVE-2025-40621
all versions
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, upda
9.8CRITICAL
CVE-2025-40620
all versions
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, upda
9.8CRITICAL
CVE-2022-36277
all versions
The 'sReferencia', 'sDescripcion', 'txtCodigo' and 'txtDescripcion' parameters, in the frmGestionStock.aspx and frmEditServicio.as
6.5MEDIUM
CVE-2022-36276
all versions
TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation o
9.9CRITICAL
CVE-2021-4046
all versions
The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability
5.4MEDIUM
CVE-2021-40853
all versions
TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this
7.2HIGH
CVE-2021-40852
all versions
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages con
6.1MEDIUM
CVE-2021-40851
all versions
TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploita
7.5HIGH
CVE-2021-40850
all versions
TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.
10.0CRITICAL
threatengine.sh