CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-51683

Critical · CVSS 9.8

mJobtime — Blind SQL Injection (unauthenticated)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-89

Description

A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server endpoint .

Search profile — drives PoC discovery

Symbols /Default.aspx/update_profile_ServerDefault.aspxupdate_profile_Server
Keywords CVE-2025-51683mJobtimemJobtime SQLimJobtime SQL injectionblind SQL injection mJobtimeupdate_profile_ServerDefault.aspx SQLimJobtime v15.7.2time management software SQLiCVE-2025-51682infoguard mJobtime
Versions: v15.7.2

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z