TCMAN GIM SQL Injection Vulnerability in ArbolID Parameter

Vulnerability

A time-based blind SQL injection vulnerability has been identified in TCMAN's GIM version 11. This vulnerability allows an attacker to retrieve, create, update, and delete databases by exploiting the ArbolID parameter in the /GIMWeb/PC/frmCorrectivosList.aspx endpoint.

Impact

Exploitation of this vulnerability allows for time-based blind SQL injection, where an attacker can manipulate SQL queries and potentially access or modify database information.

Remediation

The vulnerability has been fixed in the TCMAN GIM version 20241112 release.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.