PatchDayAlert

CVE

CVE-2024-58374

0field notes · 1digest CVSS 7.5

The verdict

Attackers can hit the Hongjing e-HR getSdutyTree endpoint without authenticating (they bypass the auth filter with a path traversal trick) and inject SQL into the codeitemid parameter. That lets them dump the entire database, including user credentials, from the underlying MSSQL server. Shadowserver observed exploitation in the wild starting July 30, 2024.

Patch urgency · Patch immediately


Daily digests