Junglewise Threat Intelligence

CVE-2021-47966: PHP Timeclock blind SQL injection in login.php

CVE-2021-47966 · Severity: high · CVSS 8.2 · Published 2026-05-15

Executive brief

PHP Timeclock, a web-based application used by businesses to track employee hours and manage payroll, is vulnerable to a security flaw that allows unauthorized access to its database. An attacker can exploit this to steal sensitive information, including employee names, login credentials, and payroll-related data. This could lead to identity theft, unauthorized access to other corporate systems, and disruption of business operations.

Technical details

A blind SQL injection vulnerability exists in PHP Timeclock version 1.04 and earlier within the 'login_userid' parameter of the login.php component. The application fails to properly sanitize user input before incorporating it into SQL queries, allowing unauthenticated remote attackers to execute arbitrary SQL commands. By sending crafted POST requests using SLEEP functions (time-based) or RLIKE conditional statements (boolean-based), an attacker can infer and extract the contents of the underlying MySQL database. This can be used to dump sensitive tables such as employee records and credentials. No patches are currently available for this legacy software.

Affected products

  • PHP Timeclock PHP Timeclock 1.04 and earlier

Timeline

  • 2021-05-03: disclosed: Initial exploit proof-of-concept published by researcher Tyler Butler
  • 2026-05-15: advisory: CVE published and added to NVD dataset

References

Related threats