Vulnerability Description
An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able to retrieve all data from the database backend. If the MSSQL backend is used the attacker can execute arbitrary SQL statements on the database backend and gain access to sensitive data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nestersoft | Worktime | <= 11.8.8 |
Related Weaknesses (CWE)
References
- https://r.sec-consult.com/worktimeThird Party Advisory
FAQ
What is CVE-2025-15560?
CVE-2025-15560 is a vulnerability with a CVSS score of 8.8 (HIGH). An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able t...
How severe is CVE-2025-15560?
CVE-2025-15560 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-15560?
Check the references section above for vendor advisories and patch information. Affected products include: Nestersoft Worktime.