Skip to content
Threat Feed
critical advisory

Unauthenticated SQL Injection and RCE in mJobTime

mJobTime builds through 15.7.3.32 contain an unauthenticated SQL injection vulnerability in Login.aspx allowing attackers to execute arbitrary commands as LocalSystem via xp_cmdshell.

CVE search metadata

CVE search record: CVE-2026-9209. Severity: critical. CVSS: 9.8. KEV: no. Product: mJobTime (<= 15.7.3.32). Brief: Unauthenticated SQL Injection and RCE in mJobTime. Brief link: https://feed.craftedsignal.io/briefs/2026-10-mjobtime-sqli/

mJobTime builds through 15.7.3.32 are vulnerable to a critical unauthenticated SQL injection vulnerability located within the Login.aspx administrative panel. The vulnerability stems from improper input validation in the 'runQueryButton' postback and 'exportSqlQuery_Server' PageMethod, which allow unauthenticated users to execute arbitrary SQL commands against the backend Sybase SQL Anywhere database. Crucially, these queries are executed with DBA or sysadmin-level database privileges.

The application relies on client-side 'sessionStorage' flags for authentication, which can be easily bypassed by an attacker submitting a specifically crafted HTTP request. By leveraging the database's administrative privileges, an attacker can invoke powerful stored procedures such as 'xp_cmdshell' to execute arbitrary operating system commands. This flaw permits complete system compromise, enabling the attacker to run code with the privileges of the database service, typically LocalSystem, with a single unauthenticated HTTP request. Organizations using mJobTime are at high risk of total system takeover and data exfiltration.

Attack Chain

  1. Attacker identifies a target instance of mJobTime running a vulnerable build (<= 15.7.3.32).
  2. Attacker crafts a malicious HTTP POST request targeting the /Login.aspx page.
  3. Attacker targets the 'runQueryButton' postback or 'exportSqlQuery_Server' PageMethod.
  4. Attacker inserts a payload designed to bypass client-side authentication checks.
  5. Attacker injects a malicious SQL query containing the 'xp_cmdshell' stored procedure.
  6. The database executes the injected SQL command with DBA/sysadmin privileges.
  7. The 'xp_cmdshell' command executes as the LocalSystem user on the underlying Windows host.
  8. Attacker gains full remote code execution, enabling persistence or further exfiltration.

Impact

Successful exploitation leads to unauthenticated remote code execution with LocalSystem privileges on the server hosting the mJobTime application. This allows attackers to install persistent backdoors, exfiltrate sensitive payroll and personnel data, move laterally within the network, or deploy ransomware. As the application is often used for workforce management, the impact of a breach includes potential exposure of extensive PII and payroll information for all company employees.

Recommendation

  1. Patch mJobTime to a version beyond 15.7.3.32 immediately to address the vulnerability in Login.aspx.
  2. Implement strict network segmentation to ensure the mJobTime web server is not reachable from the public internet.
  3. Disable 'xp_cmdshell' and similar extended stored procedures within the Sybase SQL Anywhere configuration if they are not required for business operations.
  4. Monitor web server logs for suspicious POST requests to 'Login.aspx' containing SQL-specific keywords like 'xp_cmdshell' or 'xp_read_file'.

Immediate actions

Block external access to /Login.aspx on mJobTime servers

SOC 24h

Mitigations

Upgrade mJobTime to version 15.7.3.33 or later

immediate IT Operations

CVE-2026-9209

Detection coverage 1

Detects CVE-2026-9209 Exploitation - SQL Injection Attempt in mJobTime

critical

Detects unauthenticated POST requests to Login.aspx attempting to invoke xp_cmdshell via the vulnerable runQueryButton or exportSqlQuery_Server methods.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →