Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
mJobTime Corporation

mJobTime Corporation Vendor Cyber Rating & Cyber Score

mjobtime.com

Construction’s Most Advanced Mobile Time Tracking Software Since 1994 mJobTime Corporation has been delivering easy-to-use, scalable and customizable software that allows construction and other companies to successfully manage their field resources. Our flagship product, mJobTime, delivers a substantial savings of time and money to businesses of all sizes by significantly improving and streamlining control over labor and equipment at the job site. mJobTime has been a long-time member of the Sage Software Development Partner Program, a charter member of Trimble/Viewpoint Software’s Development Partner Program, and works closely with many other construction accounting software companies to ensure seamless integrations.


mJobTime Corporation A.I CyberSecurity Scoring

mJobTime Corporation
Company Information
Website:https://http://www.mjobtime.com
Employees number:14
Number of followers:693
NAICS:5112
Industry Type:Software Development
Homepage:mjobtime.com
mJobTime Corporation Risk Score (AI oriented)
Between 750 and 799
logo
mJobTime CorporationSoftware Development
Updated:
18/03/2026
750/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
mJobTime Corporation Global Score (TPRM)
xxxx
logo
mJobTime CorporationSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

mJobTime Corporation
mJobTime CorporationFair
Current Score
750Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
750Before Incident
JUNE 2026
750Before Incident
MAY 2026
750Before Incident
APRIL 2026
750Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
749Before Incident
SEPTEMBER 2025
749Before Incident
AUGUST 2025
749Before Incident
JANUARY 2025
750Before Incident
Vulnerability
01 Jan 2025mJobTime Corporation
Mjobtime: Attackers Targeting Construction Firms Exploiting Mjobtime App Vulnerability Using MSSQL and IIS POST Request

Cyberattackers Exploit SQL Injection Flaw in Mjobtime Construction Software

748After Incident
CRITICAL-2
MJO1769418142
Cyberattackers Exploit SQL Injection Flaw in Mjobtime Construction Software Attackers are targeting construction firms by exploiting a critical vulnerability in Mjobtime, a time-tracking application widely used in the industry. The flaw, tracked as CVE-2025-51683, affects Mjobtime version 15.7.2 and enables blind SQL injection via the `/Default.aspx/update_profile_Server` endpoint. By sending crafted HTTP POST requests, threat actors can manipulate the application’s MSSQL database to execute system commands. The attack chain leverages the xp_cmdshell stored procedure, granting attackers remote command execution with the permissions of the service account often providing deep access to the Windows host. Security firm Huntress observed this pattern in three separate incidents in 2025, all tied to Mjobtime deployments in the construction sector. In one case, attackers used xp_cmdshell to run reconnaissance commands (`net user`) and test connectivity via oastify.com. In two other instances, they attempted to fetch remote payloads using wget and curl, though further intrusion was prevented. The vulnerability stems from improper input validation, allowing attackers to bypass security controls and turn the database into a remote shell behind the firewall. This not only exposes sensitive project and payroll data but also creates a foothold for lateral movement within the network. Indicators of compromise include repeated POST requests to the vulnerable endpoint and xp_cmdshell activation in MSSQL logs.
INCIDENT DETAILS -
TYPE
SQL Injection
IMPACT
Data Compromised: Sensitive project and payroll dataSystems Affected: Mjobtime version 15.7.2, MSSQL database, Windows hostOperational Impact: Lateral movement within the network, remote command execution
DATA BREACH
Type Of Data Compromised: Project and payroll dataSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for mJobTime Corporation ?
?
What was mJobTime Corporation's A.I Rankiteo Cyber Score in June 2026 ?
?
What was mJobTime Corporation's A.I Rankiteo Cyber Score in May 2026 ?
?
What was mJobTime Corporation's A.I Rankiteo Cyber Score in April 2026 ?
?
What was mJobTime Corporation's A.I Rankiteo Cyber Score in March 2026 ?
?
What was mJobTime Corporation's A.I Rankiteo Cyber Score in February 2026 ?
?
What was mJobTime Corporation's A.I Rankiteo Cyber Score in January 2026 ?
?
What was mJobTime Corporation's A.I Rankiteo Cyber Score in December 2025 ?
?
What was mJobTime Corporation's A.I Rankiteo Cyber Score in November 2025 ?
?
What was mJobTime Corporation's A.I Rankiteo Cyber Score in October 2025 ?
?
What was mJobTime Corporation's A.I Rankiteo Cyber Score in September 2025 ?
?
What was mJobTime Corporation's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on mJobTime Corporation's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with mJobTime Corporation ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view mJobTime Corporation's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?