CRITICAL
9.8 CVE-2023-54399 Published 18 Sept 2026
Hongjing e-HR SQL Injection Vulnerability
Worried this affects your website?
Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint.
The categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker can supply a crafted UNION SELECT payload to read arbitrary database content, including credential tables such as operuser.
- Affected versions: before 8.2
- Attack vector: unauthenticated remote attacker via crafted UNION SELECT payload
- Impact: arbitrary database content disclosure, including credential tables
Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
Reference: CVE-2023-54399 on NVD
← Back to Security News