TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker to directly interact with the database.
| Software | From | Fixed in |
|---|---|---|
| tcman / gim | 8.0.1 | 8.0.1.x |