CVE-2025-9977 is a medium-severity vulnerability affecting Times Software E-Payroll, where improper sanitization of POST parameters during login allows unauthenticated attackers to perform Denial of Service (DoS) attacks. SQL injection may also be possible, and command injection attempts disclose internal infrastructure details through extensive error messages. The vulnerability has a CVSS score of 5.3, indicating a low impact on confidentiality and availability, with an adjacent attack vector and low attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and the vendor's patching status is unknown.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Times Software | E-Payroll | >= 0, <= 20250121.0CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.