PatchSiren cyber security CVE debrief
CVE-2021-47966 Timeclock CVE debrief
CVE-2021-47966 describes an unauthenticated SQL injection issue in the PHP Timeclock 1.04 login flow. The weakness affects the login_userid parameter in login.php and is reported as both time-based and boolean-based blind SQL injection. In practical terms, this can let an attacker infer and extract database contents without logging in, including sensitive employee information and credentials. The supplied source record marks the vulnerability as HIGH severity and notes the NVD status as Deferred.
- Vendor
- Timeclock
- Product
- PHP Timeclock
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-15
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-15
- Advisory updated
- 2026-05-18
Who should care
Organizations running PHP Timeclock 1.04, especially any internet-facing deployments or internal timeclock systems that expose login.php. Security teams, application owners, and administrators responsible for employee-facing authentication portals should treat this as a priority if the product is in use.
Technical summary
The supplied record identifies a CWE-89 SQL injection flaw in login.php, specifically in the login_userid parameter. Because the injection is blind, attackers do not need direct query output; they can infer database responses through timing or conditional behavior. The reported impact includes unauthorized extraction of database contents, with examples in the source description mentioning employee names and credentials. The source corpus also references PHP Timeclock 1.04 and an associated advisory and proof-of-concept listing, but this debrief is limited to the defensive implications stated in the record.
Defensive priority
High. The issue is network-reachable, unauthenticated, and affects a login endpoint, which makes it suitable for rapid validation and mitigation. Even though the source record is marked Deferred by NVD, the combination of no authentication required and potential exposure of credentials warrants prompt action.
Recommended defensive actions
- Inventory whether PHP Timeclock 1.04 is deployed anywhere in your environment, including legacy or internal systems.
- Review login.php and the login_userid parameter handling for SQL injection exposure.
- Apply vendor or project remediation if available from the referenced PHP Timeclock distribution or advisory.
- Restrict exposure of the application to trusted networks until remediation is in place.
- Rotate any credentials or secrets that may have been stored in or exposed through the affected database.
- Monitor application and database logs for unusual login.php POST activity and repeated timing-based requests.
- If the product cannot be patched quickly, isolate or retire the affected instance.
Evidence notes
The source corpus ties this CVE to PHP Timeclock 1.04 through the referenced project pages and advisory links. NVD lists the weakness as CWE-89 and the status as Deferred in the supplied record. The corpus does not provide KEV placement or ransomware association, so those are not asserted here. Vendor attribution is low-confidence in the supplied metadata, so the product is identified from the referenced sources rather than from a confirmed vendor name.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-47966 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-47966
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-47966 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-47966
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://sourceforge.net/projects/timeclock/files/PHP%20Timeclock/PHP%20Timeclock%201.04/
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/49849
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/php-timeclock-sql-injection-via-login-php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.