CVE-2025-40624
Last modified
CVE-2025-40624 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ and “email” parameters of the ‘updatePassword’ endpoint.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tcman | Gim | 11.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-40624?
How severe is CVE-2025-40624?
How do I fix CVE-2025-40624?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40619Bookgy does not provide for proper authorisation control in …7.5
- CVE-2025-4062A vulnerability has been found in code-projects Theater Seat…7.8
- CVE-2025-40620SQL injection in TCMAN's GIM v11. This vulnerability allows …9.8
- CVE-2025-40621SQL injection in TCMAN's GIM v11. This vulnerability allows …9.8
- CVE-2025-40622SQL injection in TCMAN's GIM v11. This vulnerability allows …9.8
- CVE-2025-40623SQL injection in TCMAN's GIM v11. This vulnerability allows …9.8
- CVE-2025-40625Unrestricted file upload in TCMAN's GIM v11. This vulnerabil…9.8
- CVE-2025-40626Reflected Cross-Site Scripting (XSS) vulnerability in Abante…6.1
- CVE-2025-40627Reflected Cross-Site Scripting (XSS) vulnerability in Abante…6.1
- CVE-2025-40628SQL injection vulnerability in DomainsPRO 1.2. This vulnerab…9.3
- CVE-2025-40629PNETLab 4.2.10 does not properly sanitize user inputs in its…8.7
- CVE-2025-4063A vulnerability was found in code-projects Student Informati…7.8
Are you affected by CVE-2025-40624?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
