Impact
An unauthenticated SQL injection flaw exists in the Login.aspx admin panel of mJobTime, where POST handlers such as runQueryButton and the exportSqlQuery_Server PageMethod execute caller‑supplied SQL against the internal Sybase SQL Anywhere database with DBA or sysadmin privileges. By injecting statements that invoke extended stored procedures like xp_cmdshell or xp_read_file, an attacker can run arbitrary commands and read files, achieving remote code execution as the LocalSystem account. The weakness arises from a lack of server‑side authentication and privileged database access (CWE‑250, CWE‑306).
Affected Systems
Versions of the mJobTime application up to and including build 15.7.3.32 are affected; any earlier releases likely share the same flaw. The product is distributed by the vendor mJob under the name mJobTime.
Risk and Exploitability
The CVSS score of 9.3 denotes a critical severity. Although the EPSS score is not provided and the vulnerability is not listed in CISA’s KEV catalog, the flaw can be leveraged through a single unauthenticated HTTP request targeting the exposed admin endpoints. Attackers only need network connectivity to the web server to submit arbitrary SQL and trigger arbitrary OS commands, implying a high likelihood of exploitation in reachable environments.
OpenCVE Enrichment