Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2023-54399: Hongjing e‑HR allows data theft via crafted request

CVE-2023-54399 · published 23 days ago
Summary

The Hongjing e‑HR system (versions before 8.2) lets anyone on the internet send a specially formed request to the /servlet/codesettree page and retrieve data from its database, including user credentials. This happens because the system does not properly clean the input it receives. Apply the vendor’s update or patch the affected page to block unsafe input.

What to do
  • Update hongjing e-hr to version 8.2 or later.
Affected software
VendorProductAffected versions
hongjing e-hr < 8.2
Original advisory text
Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree
Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker can supply a crafted UNION SELECT payload to read arbitrary database content, including credential tables such as operuser. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-89SQL Injection
Timeline
Published18 Sep 2026
Updated11 Oct 2026
First seen18 Sep 2026
Sources
CVE-2023-54399 · MITRE
Track software like this
Free during beta