AI description
CVE-2025-51683 identifies a blind SQL Injection (SQLi) vulnerability present in mJobtime version 15.7.2. This flaw enables unauthenticated attackers to execute arbitrary SQL statements. The vulnerability is exploited by sending a specially crafted POST request to the `/Default.aspx/update_profile_Server` endpoint. This issue was uncovered during an external penetration test and could potentially lead to remote code execution and the leakage of sensitive information.
- Description
- A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server endpoint .
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- mjobtime
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-89
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
12
Legit construction software quietly exposed backend MSSQL. Attackers took advantage via blind SQL injection (CVE-2025-51683). No malware required. Just xp_cmdshell and permissions doing their job. Inventory your dependencies, not just your apps. https://t.co/aLrIBBzYsH
@HuntressLabs
24 Jan 2026
7990 Impressions
9 Retweets
53 Likes
11 Bookmarks
0 Replies
1 Quote
CVE-2025-51683 A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the … https://t.co/qvGyUKz62w
@CVEnew
1 Dec 2025
149 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
We've published technical details for CVE-2025-51682 and CVE-2025-51683 – two vulnerabilities in the time management software mJobTime that lead to unauthenticated RCE via SQLi by @dario_weiss: https://t.co/CP9sNeRdQH
@InfoGuard_Labs
25 Nov 2025
190 Impressions
2 Retweets
5 Likes
3 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mjobtime:mjobtime:15.7.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC0C873D-A6A8-4FB3-A7AC-07DBC8ED72A9"
}
],
"operator": "OR"
}
]
}
]