/Vulnerability Library

mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCE

CVE-2025-51683
Verified

Description

mJobtime v15.7.2 contains a sql injection caused by crafted POST request to /Default.aspx/update_profile_Server, letting unauthenticated attackers execute arbitrary SQL statements remotely, exploit requires no special privileges.

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Affected Product

mjobtime

Published Date

September 1, 2026

Template Author

0x_akoko, pdteam

CVE-2025-51683.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-51683
CWE ID:
cwe-89

References

https://labs.infoguard.ch/advisories/cve-2025-51682_cve-2025-51683_time_management_softare_sqli-rce/https://nvd.nist.gov/vuln/detail/CVE-2025-51683https://github.com/advisories/GHSA-gp72-w5fg-q33m

Remediation Steps

Update to the latest version of mJobtime.