Junglewise Threat Intelligence

CVE-2023-54399: Hongjing e-HR SQL injection in codesettree endpoint

CVE-2023-54399 · Severity: critical · CVSS 9.8 · Published 2026-09-18

Executive brief

Hongjing e-HR is a human resource management system used by organizations to manage employee data and payroll. The application contains an unauthenticated SQL injection vulnerability that allows attackers to read sensitive database contents, including employee credentials and personal information, without requiring valid login credentials.

Technical details

The /servlet/codesettree endpoint fails to properly sanitize the categories query parameter after HRMS-encoding is stripped, allowing SQL UNION-based injection attacks. An unauthenticated remote attacker can craft a payload to execute arbitrary SQL queries and exfiltrate sensitive data from tables such as operuser (credential tables). The vulnerability affects versions before 8.2 and has been observed in active exploitation since October 2023.

Affected products

  • Hongjing e-HR before 8.2

Timeline

  • 2023-10-14: exploited: Exploitation evidence first observed by Shadowserver Foundation
  • 2023-07-09: disclosed

References