SQL Injection Vulnerability in Haichang OA by cnhcit.com
CVE-2024-32323

Currently unrated

Key Information:

Vendor

cnhcit.com

Vendor
CVE Published:
17 July 2025

What is CVE-2024-32323?

An SQL Injection vulnerability in Haichang OA version 1.0.0 allows remote attackers to exploit the 'if' parameter in 'hcit.project.rte.agents.UploadImages.class'. This weakness could enable unauthorized access to sensitive data, causing significant risk to users. Proper validation of input parameters is essential to mitigate potential attacks that could lead to information leakage.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-32323 : SQL Injection Vulnerability in Haichang OA by cnhcit.com