CVE
CVE-2024-58374
0field notes · 1digest CVSS 7.5
The verdict
Attackers can hit the Hongjing e-HR getSdutyTree endpoint without authenticating (they bypass the auth filter with a path traversal trick) and inject SQL into the codeitemid parameter. That lets them dump the entire database, including user credentials, from the underlying MSSQL server. Shadowserver observed exploitation in the wild starting July 30, 2024.
Patch urgency · Patch immediately
Daily digests