Junglewise Threat Intelligence

CVE-2025-51682: mJobTime client-side authorization bypass in administrative interface

CVE-2025-51682 · Severity: critical · CVSS 9.8 · Published 2025-12-01

Executive brief

mJobTime, a workforce management and time-tracking software, contains a critical security flaw where administrative access is controlled by the user's browser rather than the server. An unauthorized person can bypass the login screen by modifying simple web code or sending specific requests to access sensitive administrative features. This could allow an attacker to view employee data, steal email credentials, or gain full control over the underlying database and server.

Technical details

mJobTime 15.7.2 suffers from client-side enforcement of server-side security (CWE-602). The application performs authorization checks within frontend JavaScript, such as verifying if a username is set to 'SUPERVISOR' or checking for a 'success' string in a response before granting access to administrative pages like AdminScreen.aspx. An unauthenticated attacker can bypass these checks by intercepting and modifying HTTP responses or by directly navigating to administrative endpoints. Successful exploitation allows access to sensitive information including SMTP credentials, user lists, and a functional administrative interface that supports arbitrary SQL execution. While an emergency update was released, initial reports indicated that some endpoints remained accessible without authentication.

Affected products

  • mJobTime mJobTime 15.7.2

Timeline

  • 2025-02-20: disclosed: First contact with vendor
  • 2025-02-21: patched: Vendor deployed emergency update
  • 2025-05-21: other: CVEs requested from MITRE
  • 2025-12-01: advisory: NVD publication date

References

Related threats