SQL Injection in NesterSoft WorkTime
Vulnerability Description
An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able to retrieve all data from the database backend. If the MSSQL backend is used the attacker can execute arbitrary SQL statements on the database backend and gain access to sensitive data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15560
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Tobias Niemann, SEC Consult Vulnerability Lab
- Daniel Hirschberger, SEC Consult Vulnerability Lab
- Thorger Jansen, SEC Consult Vulnerability Lab
- Marius Renner, SEC Consult Vulnerability Lab
References
More from NesterSoft Inc.
View All →Affected Vendor
NesterSoft Inc.
View all reports →