CVE-2025-41013: Tcman Gim

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.

Affected products

  • Tcman Gim: before 2025-04-01 (fixed in 2025-04-01)

Published 2025-12-02. Last modified 2026-09-25.