SQL Injection Vulnerability in Hongjing e-HR Product by Hongjing
CVE-2023-54399
Key Information:
Badges
What is CVE-2023-54399?
The Hongjing e-HR software prior to version 8.2 is susceptible to a SQL injection vulnerability located at the /servlet/codesettree endpoint. This flaw allows an unauthenticated remote attacker to inject a crafted UNION SELECT statement through the categories query parameter, potentially exposing sensitive database contents, including user credentials. The issue arises from insufficient input sanitization once HRMS-encoding is removed. The infiltration method was first detected by the Shadowserver Foundation on October 14, 2023.
Affected Version(s)
e-HR 0 < 8.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
