CVE-2025-51683: SQL Injection
A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/updateprofileServer endpoint .
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mJobtimeto a version that resolves this vulnerability.Fixed in 15.7.2 - Compensating control
Mitigate exposure by blocking unauthenticated access to the /Default.aspx/update_profile_Server endpoint (and related application endpoints) at the network layer (e.g., firewall/WAF), limiting it to authenticated/authorized clients only.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51683?
CVE-2025-51683 is classified as a critical severity vulnerability due to its potential for unauthorized access and data manipulation.
How do I fix CVE-2025-51683?
To fix CVE-2025-51683, update mJobtime to the latest version that addresses this SQL injection vulnerability.
What type of vulnerability is CVE-2025-51683?
CVE-2025-51683 is a blind SQL Injection vulnerability that allows attackers to execute arbitrary SQL statements.
Can CVE-2025-51683 be exploited remotely?
Yes, CVE-2025-51683 can be exploited remotely by unauthenticated attackers via a crafted POST request.
Which versions of mJobtime are affected by CVE-2025-51683?
CVE-2025-51683 specifically affects mJobtime version 15.7.2.