Description

An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able to retrieve all data from the database backend. If the MSSQL backend is used the attacker can execute arbitrary SQL statements on the database backend and gain access to sensitive data.

INFO

Published Date :

2026-02-19T10:48:43.486Z

Last Modified :

2026-02-23T18:29:08.299Z

Source :

SEC-VLab
AFFECTED PRODUCTS

The following products are affected by CVE-2025-15560 vulnerability.

Vendors Products
Nestersoft
  • Worktime
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-15560.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact