Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2023-54399: Hongjing e‑HR allows data theft via crafted request
CVE-2023-54399 · published 23 days ago
Summary
The Hongjing e‑HR system (versions before 8.2) lets anyone on the internet send a specially formed request to the /servlet/codesettree page and retrieve data from its database, including user credentials. This happens because the system does not properly clean the input it receives. Apply the vendor’s update or patch the affected page to block unsafe input.
What to do
- Update hongjing e-hr to version 8.2 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| hongjing | e-hr | < 8.2 |
Original advisory text
Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree
Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker can supply a crafted UNION SELECT payload to read arbitrary database content, including credential tables such as operuser. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
References
- https://www.cnvd.org.cn/flaw/show/CNVD-2023-08743
- https://cn-sec.com/archives/1861976.html
- https://www.cnblogs.com/pursue-security/p/17704093.html
- https://www.cloudsek.com/blog/mozi-resurfaces-as-androxgh0st-botnet-unraveling-t...
- https://www.vulncheck.com/advisories/hongjing-e-hr-sql-injection-via-servlet-cod...
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-89SQL Injection
Timeline
Published18 Sep 2026
Updated11 Oct 2026
First seen18 Sep 2026
Track software like this
Free during beta