{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/mjobtime/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mjobtime:mjobtime:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-9209"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mJobTime (\u003c= 15.7.3.32)"],"_cs_severities":["critical"],"_cs_tags":["injection","rce","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["mJobTime"],"content_html":"\u003cp\u003emJobTime builds through 15.7.3.32 are vulnerable to a critical unauthenticated SQL injection vulnerability located within the Login.aspx administrative panel. The vulnerability stems from improper input validation in the 'runQueryButton' postback and 'exportSqlQuery_Server' PageMethod, which allow unauthenticated users to execute arbitrary SQL commands against the backend Sybase SQL Anywhere database. Crucially, these queries are executed with DBA or sysadmin-level database privileges.\u003c/p\u003e\n\u003cp\u003eThe application relies on client-side 'sessionStorage' flags for authentication, which can be easily bypassed by an attacker submitting a specifically crafted HTTP request. By leveraging the database's administrative privileges, an attacker can invoke powerful stored procedures such as 'xp_cmdshell' to execute arbitrary operating system commands. This flaw permits complete system compromise, enabling the attacker to run code with the privileges of the database service, typically LocalSystem, with a single unauthenticated HTTP request. Organizations using mJobTime are at high risk of total system takeover and data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target instance of mJobTime running a vulnerable build (\u0026lt;= 15.7.3.32).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request targeting the /Login.aspx page.\u003c/li\u003e\n\u003cli\u003eAttacker targets the 'runQueryButton' postback or 'exportSqlQuery_Server' PageMethod.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a payload designed to bypass client-side authentication checks.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious SQL query containing the 'xp_cmdshell' stored procedure.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected SQL command with DBA/sysadmin privileges.\u003c/li\u003e\n\u003cli\u003eThe 'xp_cmdshell' command executes as the LocalSystem user on the underlying Windows host.\u003c/li\u003e\n\u003cli\u003eAttacker gains full remote code execution, enabling persistence or further exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to unauthenticated remote code execution with LocalSystem privileges on the server hosting the mJobTime application. This allows attackers to install persistent backdoors, exfiltrate sensitive payroll and personnel data, move laterally within the network, or deploy ransomware. As the application is often used for workforce management, the impact of a breach includes potential exposure of extensive PII and payroll information for all company employees.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch mJobTime to a version beyond 15.7.3.32 immediately to address the vulnerability in Login.aspx.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation to ensure the mJobTime web server is not reachable from the public internet.\u003c/li\u003e\n\u003cli\u003eDisable 'xp_cmdshell' and similar extended stored procedures within the Sybase SQL Anywhere configuration if they are not required for business operations.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to 'Login.aspx' containing SQL-specific keywords like 'xp_cmdshell' or 'xp_read_file'.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-08T17:11:02Z","date_published":"2026-10-08T17:11:02Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mjobtime-sqli/","summary":"mJobTime builds through 15.7.3.32 contain an unauthenticated SQL injection vulnerability in Login.aspx allowing attackers to execute arbitrary commands as LocalSystem via xp_cmdshell.","title":"Unauthenticated SQL Injection and RCE in mJobTime","url":"https://feed.craftedsignal.io/briefs/2026-10-mjobtime-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - MJobTime","version":"https://jsonfeed.org/version/1.1"}