CVE-2025-41013Critical· 9.8▾ MidnightSQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.
gim < 2025-04-01Upgrade past the affected range:
gim 2025-04-01Connected by shared product, vendor, weakness, or advisory.
CVE-2025-41015High· 7.5User Enumeration Vulnerability in TCMAN GIM v11 version 20250304
CVE-2025-41014High· 7.5User Enumeration Vulnerability in TCMAN GIM v11 version 20250304
CVE-2025-10601High· 7.3A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0
CVE-2025-10602Medium· 6.3A vulnerability was found in SourceCodester Online Exam Form Submission 1.0
CVE-2025-10598High· 7.3A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0
CVE-2025-10599High· 7.3A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0