Description
An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able to retrieve all data from the database backend. If the MSSQL backend is used the attacker can execute arbitrary SQL statements on the database backend and gain access to sensitive data.
INFO
Published Date :
2026-02-19T10:48:43.486Z
Last Modified :
2026-02-23T18:29:08.299Z
Source :
SEC-VLab
AFFECTED PRODUCTS
The following products are affected by CVE-2025-15560 vulnerability.
| Vendors | Products |
|---|---|
| Nestersoft |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-15560.
| URL | Resource |
|---|---|
| https://r.sec-consult.com/worktime |
|
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact