CRITICAL 9.8 CVE-2023-54399 Published 18 Sept 2026

Hongjing e-HR SQL Injection Vulnerability

Worried this affects your website?

Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint.

The categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker can supply a crafted UNION SELECT payload to read arbitrary database content, including credential tables such as operuser.

  • Affected versions: before 8.2
  • Attack vector: unauthenticated remote attacker via crafted UNION SELECT payload
  • Impact: arbitrary database content disclosure, including credential tables

Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.

Reference: CVE-2023-54399 on NVD

← Back to Security News