CVE-2025-40621
Last modified
CVE-2025-40621 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ parameter of the ‘ValidateUserAndGetData’ endpoint.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tcman | Gim | 11.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-40621?
How severe is CVE-2025-40621?
How do I fix CVE-2025-40621?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40616Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy…6.1
- CVE-2025-40617SQL injection vulnerability in Bookgy. This vulnerability co…9.8
- CVE-2025-40618SQL injection vulnerability in Bookgy. This vulnerability co…9.8
- CVE-2025-40619Bookgy does not provide for proper authorisation control in …7.5
- CVE-2025-4062A vulnerability has been found in code-projects Theater Seat…7.8
- CVE-2025-40620SQL injection in TCMAN's GIM v11. This vulnerability allows …9.8
- CVE-2025-40622SQL injection in TCMAN's GIM v11. This vulnerability allows …9.8
- CVE-2025-40623SQL injection in TCMAN's GIM v11. This vulnerability allows …9.8
- CVE-2025-40624SQL injection in TCMAN's GIM v11. This vulnerability allows …9.8
- CVE-2025-40625Unrestricted file upload in TCMAN's GIM v11. This vulnerabil…9.8
- CVE-2025-40626Reflected Cross-Site Scripting (XSS) vulnerability in Abante…6.1
- CVE-2025-40627Reflected Cross-Site Scripting (XSS) vulnerability in Abante…6.1
Are you affected by CVE-2025-40621?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
