Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-9209— mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx

Quick assessment

Affected
mJob mJobTime
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 mJobTime 15.7.3.32 及更早版本中,Login.aspx 管理面板的处理程序存在一个未认证的 SQL 执行漏洞。其中,runQueryButton 的回发操作和 exportSqlQuery_Server PageMethod 会使用 DBA/sysadmin 权限,对后端的 Sybase SQL Anywhere 数据库执行调用者提供的 SQL 语句。除了依赖客户端 sessionStorage 标志外,服务端未实施任何额外的身份验证机制。攻击者可通过这些暴露的端点提交任意 SQL 语句,从而

CVSS 9.8 · Critical

Affected Version Matrix 1

VendorProduct Version RangeStatus
mJob mJobTime ≤ 15.7.3.32 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-9209

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx
Source: CVE Program / CVE List V5
Vulnerability Description
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attackers can submit arbitrary SQL through these exposed endpoints to invoke xp_cmdshell and xp_read_file, achieving pre-authentication remote code execution as LocalSystem via a single HTTP request.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
mJob mJobTime 0 ~ 15.7.3.32 -

II. Public POCs for CVE-2026-9209

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9209

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-9209 (1)

Security Blog Posts for CVE-2026-9209 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-9209

No comments yet


Leave a comment