CVE-2025-15563
Estado: AnalizadaMedia (5.3)—
Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. No authorization check is applied here.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.27%
- Percentil entre todas las CVEs puntuadas: 17
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-862
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-15563",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-15563",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-02-20T20:34:46.208230Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
"affectedData": [
{
"vendor": "NesterSoft Inc.",
"product": "WorkTime (on-prem/cloud)",
"versions": [
{
"status": "affected",
"version": "<= 11.8.8"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-02-19T11:15:56.983",
"references": [
{
"url": "https://r.sec-consult.com/worktime",
"tags": [
"Third Party Advisory"
],
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. No authorization check is applied here."
},
{
"lang": "es",
"value": "Cualquier usuario no autenticado puede restablecer la configuración de la base de datos local de WorkTime enviando una solicitud HTTP específica al servidor de WorkTime. No se aplica ninguna comprobación de autorización aquí."
}
],
"lastModified": "2026-06-17T08:38:02.130",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nestersoft:worktime:*:*:*:*:cloud:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8A53FE8-6F29-462D-B7EB-C3E4F25DBEC3",
"versionEndIncluding": "11.8.8"
},
{
"criteria": "cpe:2.3:a:nestersoft:worktime:*:*:*:*:on-premise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A831FDF-1B71-48B4-BA2D-D2EFB151161A",
"versionEndIncluding": "11.8.8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "551230f0-3615-47bd-b7cc-93e92e730bbf"
}