mJobTime Corporation A.I CyberSecurity Scoring
mJobTime Corporation
Company Information
Website:https://http://www.mjobtime.com
Employees number:14
Number of followers:693
NAICS:5112
Industry Type:Software Development
Homepage:mjobtime.com
mJobTime Corporation Risk Score (AI oriented)
Between 750 and 799
mJobTime CorporationSoftware Development
Updated:
18/03/2026
18/03/2026
750/1000
Fair
Baa
mJobTime Corporation Global Score (TPRM)
xxxx
mJobTime CorporationSoftware Development
Score locked

mJobTime CorporationFair
Current Score
750Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
750
JUNE 2026
750
MAY 2026
750
APRIL 2026
750
MARCH 2026
750
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
749
SEPTEMBER 2025
749
AUGUST 2025
749
JANUARY 2025
750
Vulnerability
01 Jan 2025 • mJobTime Corporation
Mjobtime: Attackers Targeting Construction Firms Exploiting Mjobtime App Vulnerability Using MSSQL and IIS POST Request
Cyberattackers Exploit SQL Injection Flaw in Mjobtime Construction Software
748
CRITICAL-2
MJO1769418142
Cyberattackers Exploit SQL Injection Flaw in Mjobtime Construction Software
Attackers are targeting construction firms by exploiting a critical vulnerability in Mjobtime, a time-tracking application widely used in the industry. The flaw, tracked as CVE-2025-51683, affects Mjobtime version 15.7.2 and enables blind SQL injection via the `/Default.aspx/update_profile_Server` endpoint.
By sending crafted HTTP POST requests, threat actors can manipulate the application’s MSSQL database to execute system commands. The attack chain leverages the xp_cmdshell stored procedure, granting attackers remote command execution with the permissions of the service account often providing deep access to the Windows host.
Security firm Huntress observed this pattern in three separate incidents in 2025, all tied to Mjobtime deployments in the construction sector. In one case, attackers used xp_cmdshell to run reconnaissance commands (`net user`) and test connectivity via oastify.com. In two other instances, they attempted to fetch remote payloads using wget and curl, though further intrusion was prevented.
The vulnerability stems from improper input validation, allowing attackers to bypass security controls and turn the database into a remote shell behind the firewall. This not only exposes sensitive project and payroll data but also creates a foothold for lateral movement within the network. Indicators of compromise include repeated POST requests to the vulnerable endpoint and xp_cmdshell activation in MSSQL logs.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for mJobTime Corporation ??
What was mJobTime Corporation's A.I Rankiteo Cyber Score in June 2026 ??
What was mJobTime Corporation's A.I Rankiteo Cyber Score in May 2026 ??
What was mJobTime Corporation's A.I Rankiteo Cyber Score in April 2026 ??
What was mJobTime Corporation's A.I Rankiteo Cyber Score in March 2026 ??
What was mJobTime Corporation's A.I Rankiteo Cyber Score in February 2026 ??
What was mJobTime Corporation's A.I Rankiteo Cyber Score in January 2026 ??
What was mJobTime Corporation's A.I Rankiteo Cyber Score in December 2025 ??
What was mJobTime Corporation's A.I Rankiteo Cyber Score in November 2025 ??
What was mJobTime Corporation's A.I Rankiteo Cyber Score in October 2025 ??
What was mJobTime Corporation's A.I Rankiteo Cyber Score in September 2025 ??
What was mJobTime Corporation's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on mJobTime Corporation's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with mJobTime Corporation ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view mJobTime Corporation's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?