CVE Explorer
CVE-2025-9977
Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not sanitized properly, which allows an unauthenticated attacker to perform DoS attacks. SQL injection attacks might also be feasible, although so far creating a working exploit has been prevented probably by backend filtering mechanisms.
Additionally, command injection attempts cause the application to return extensive error messages disclosing some information about the internal infras
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-209","description":"CWE-209 Generation of Error Message Containing Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2ee7f645cef9ebdf6cc5bbc99fd3206c63542c7b985377f406c60ff41b5d21e0 · sha256:75ba140d2a0730d3… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2ee7f645cef9ebdf6cc5bbc99fd3206c63542c7b985377f406c60ff41b5d21e0 · sha256:75ba140d2a0730d3… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"E-Payroll","vendor":"Times Software","versions":[{"lessThanOrEqual":"20250121.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2ee7f645cef9ebdf6cc5bbc99fd3206c63542c7b985377f406c60ff41b5d21e0 · sha256:75ba140d2a0730d3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NO…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2ee7f645cef9ebdf6cc5bbc99fd3206c63542c7b985377f406c60ff41b5d21e0 · sha256:75ba140d2a0730d3… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-209","description":"CWE-209 Generation of Error Message Containing Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2ee7f645cef9ebdf6cc5bbc99fd3206c63542c7b985377f406c60ff41b5d21e0 · sha256:75ba140d2a0730d3… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2ee7f645cef9ebdf6cc5bbc99fd3206c63542c7b985377f406c60ff41b5d21e0 · sha256:75ba140d2a0730d3… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["third-party-advisory"],"url":"https://cert.pl/en/posts/2025/11/CVE-2025-9977"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2ee7f645cef9ebdf6cc5bbc99fd3206c63542c7b985377f406c60ff41b5d21e0 · sha256:75ba140d2a0730d3… · /containers/cna/references/0
{"tags":["product"],"url":"https://www.timesoftsg.com.sg/payroll-software/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2ee7f645cef9ebdf6cc5bbc99fd3206c63542c7b985377f406c60ff41b5d21e0 · sha256:75ba140d2a0730d3… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.