Vendor
critical
threat
SQL Injection in Hongjing e-HR /servlet/codesettree
1 rule 1 TTP 1 CVEHongjing e-HR versions prior to 8.2 are vulnerable to unauthenticated SQL injection via the categories parameter in the /servlet/codesettree endpoint, allowing remote attackers to extract sensitive database content.
exploited
e-HR
web-application
injection
vurnerability
1r
1t
1c
high
threat
Unauthenticated SQL Injection and Authentication Bypass in Hongjing e-HR
1 rule 2 TTPs 1 CVEHongjing e-HR contains an unauthenticated SQL injection and path traversal vulnerability (CVE-2024-58374) allowing attackers to bypass authentication and exfiltrate database contents via the getSdutyTree servlet.
exploited
e-HR
vulnerability
sql-injection
web-application
cve-2024-58374
1r
2t
1c