CVE-2025-51683Disclosure(mjobtime / mjobtime)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch mjobtime mjobtime systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server endpoint .

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mjobtime

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-01-27); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
mjobtime

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-01-27: 2Mentions · 2026-01-30: 1Mentions · 2026-09-01: 1PoC Mentioned / Linked · 2026-01-27: 1PoC Mentioned / Linked · 2026-09-01: 1Active Exploitation · 2026-01-30: 1Patch / Workaround · 2026-01-27: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-30: 1Technical Details · 2026-09-01: 101-2701-3009-01
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure2
2026-01-301
Active Exploitation1
2026-09-011
Disclosure1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-51683 - critical 🚨 mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCE > mJobtime v15.7.2 contains a sql injection caused by crafted POST request to /Default.... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-51683 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE-2025-51683, a blind SQL injection in mJobTime v15.7.2 that can lead to RCE, and shares a link to a Library (likely PoC/Nuclei template) but provides no evidence of active exploitation or remediation.

    020162771
    1.3K followersView on X
  • Ostorlab@OstorlabSec
    Disclosure

    🚨 CVE-2025-51683 : CRITICAL SQLi ALERT 🚨 @mJobtime A critical unauthenticated blind SQL injection vulnerability has been disclosed in mJobtime, a workforce management and time-tracking platform widely used in construction and field service industries. Risk Severity: Critical (CVSS 9.8, trending, public PoC available, ransomware-relevant) Impact: • Complete backend database compromise • Exfiltration of employee PII & payroll records • Credential theft and authentication bypass • Ransomware extortion & regulatory exposure (GDPR/CCPA) • Potential OS-level command execution via SQL Server Root Cause: CWE-89 (SQL Injection). The profile update endpoint directly concatenates user-supplied input into SQL queries without sanitization or parameterization, enabling unauthenticated blind SQL injection. Attackers can: • Exploit the /Default.aspx/update_profile_Server endpoint without credentials • Enumerate and exfiltrate database contents via time-based inference • Modify or delete payroll and employee records • Extract admin credentials and pivot laterally • Establish persistence through malicious DB objects Are You Affected? Vulnerable: mJobtime 15.7.2 Scope: Internet-accessible on-prem or cloud deployments Immediate Action Required: Update: Upgrade to mJobtime 15.7.3+ immediately Mitigation: Restrict access to VPN-only and deploy WAF rules blocking SQLi Audit: Hunt for POST requests to the update profile endpoint and abnormal DB query timing Workforce platforms are high-value ransomware targets. Treat this as an emergency fix. 🛡️ #mjobtime #security #ostorlabCVE

    Post summary

    A critical unauthenticated blind SQL injection in mJobtime 15.7.2 is disclosed, with technical details and immediate patch recommendations provided. No evidence of active exploitation or exploit code is mentioned.

    0001086
    582 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Construction Firms Targeted via mJobTime Blind SQLi to Trigger MSSQL xp_cmdshell RCE Attackers are exploiting a blind SQL injection in **mJobTime v15.7.2** (CVE-2025-51683) by sending crafted IIS **POST** requests to `/Default.aspx/update_profile_Server`, enabling **xp_cmdshell** and executing OS commands on the Windows host. This gives threat actors a direct path from a public web endpoint to database-driven remote command execution, risking payroll/project data theft and deeper network compromise. 🎯 Target: Global/Construction #️⃣ Category: #CVE2025_51683 #mJobTime #SQLInjection #MSSQL #xp_cmdshell #IIS #RCE #Construction #ThreatIntel 🔗 URL: https://cybersecuritynews.com/attackers-exploiting-mjobtime-app-vulnerability/

    Post summary

    Attackers are actively exploiting CVE-2025-51683 via a blind SQL injection in mJobTime, enabling remote command execution through xp_cmdshell, posing a direct threat to construction firms’ data and network security.

    0000046
    196 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    Critical vulnerability CVE-2025-51683 found in mJobTime v15.7.2 exposes construction firms to cyber attacks. Immediate action required! Link: https://thedailytechfeed.com/mjobtime-vulnerability-puts-construction-firms-at-risk-of-cyber-attacks/ #Vulnerability #CyberThreat #Security #Software #Construction #Risk #Technology #Hacking #Data #CyberDefense #CVE #mJobTime #IT #Attack #Protection #SQL #Industry #Alert #Breach #Network

    Post summary

    The post announces the critical CVE‑2025‑51683 affecting mJobTime v15.7.2 and urges immediate action for construction firms.

    0000050
    239 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmjobtimemjobtime15.7.2--

Explore more