CVE-2025-51683
Critical · CVSS 9.8mJobtime — Blind SQL Injection (unauthenticated)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-89
Description
A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server endpoint .
Search profile — drives PoC discovery
Symbols /Default.aspx/update_profile_ServerDefault.aspxupdate_profile_Server
Keywords CVE-2025-51683mJobtimemJobtime SQLimJobtime SQL injectionblind SQL injection mJobtimeupdate_profile_ServerDefault.aspx SQLimJobtime v15.7.2time management software SQLiCVE-2025-51682infoguard mJobtime
Versions: v15.7.2
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z