Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xp_cmdshell and xp_read_file, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request. | |
| Title | mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx | |
| Weaknesses | CWE-250 CWE-306 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T17:52:00.960Z
Reserved: 2026-05-21T17:27:06.316Z
Link: CVE-2026-9209
No data.
Status : Received
Published: 2026-10-08T15:17:57.677
Modified: 2026-10-08T15:17:57.677
Link: CVE-2026-9209
No data.
OpenCVE Enrichment
Updated: 2026-10-08T17:30:17Z