CVE Database
/

CVE-2025-15563

Back to search

CVE-2025-15563

Published: Feb 19, 2026

Modified: Feb 20, 2026

PUBLISHED

Description

Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. No authorization check is applied here.

VendorProductVersions

NesterSoft Inc.

WorkTime (on-prem/cloud)

affected
<= 11.8.8

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now