{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/hongjing/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2024-58374"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["e-HR"],"_cs_severities":["high"],"_cs_tags":["vulnerability","sql-injection","web-application","cve-2024-58374"],"_cs_type":"threat","_cs_vendors":["Hongjing"],"content_html":"\u003cp\u003eHongjing e-HR software is affected by an unauthenticated vulnerability in the getSdutyTree servlet. Attackers leverage a path traversal sequence within the request URI to bypass the oauthservlet authentication filter, allowing them to reach protected endpoints without credentials. Once authentication is bypassed, attackers can perform UNION-based SQL injection by manipulating the unsanitized codeitemid parameter. This allows for the unauthorized retrieval of sensitive information from the backend Microsoft SQL Server database, including user credentials. Exploitation in the wild was first identified by the Shadowserver Foundation on July 30, 2024. This vulnerability poses a significant risk to organizations using the e-HR platform as it facilitates full database exfiltration through unauthenticated access.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends a crafted HTTP GET request to the getSdutyTree servlet endpoint.\u003c/li\u003e\n\u003cli\u003eRequest includes a path traversal sequence (e.g., ../) in the URI to bypass the oauthservlet authentication filter.\u003c/li\u003e\n\u003cli\u003eThe application fails to validate the request path, granting access to the endpoint without an active session.\u003c/li\u003e\n\u003cli\u003eAttacker includes a malicious UNION-based SQL payload within the codeitemid parameter.\u003c/li\u003e\n\u003cli\u003eThe application passes the unsanitized input directly to the backend Microsoft SQL Server database query.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected SQL command and returns the results of the UNION query within the application response.\u003c/li\u003e\n\u003cli\u003eAttacker parses the response to exfiltrate user credentials and other sensitive data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote, unauthenticated attackers to bypass security controls and perform unauthorized data exfiltration from the e-HR database. This can lead to a complete compromise of user credentials and the exposure of sensitive organizational information, potentially facilitating further lateral movement or additional system access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy webserver logs monitoring to detect URI patterns containing path traversal sequences directed at the getSdutyTree servlet.\u003c/li\u003e\n\u003cli\u003eAudit Microsoft SQL Server database logs for unexpected UNION SELECT or sensitive information schema queries originating from the application service account.\u003c/li\u003e\n\u003cli\u003eApply vendor-supplied patches for CVE-2024-58374 on all internet-facing e-HR instances immediately.\u003c/li\u003e\n\u003cli\u003eInspect web server access logs for anomalous GET requests containing non-alphanumeric characters or SQL keywords in the codeitemid parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T18:56:47Z","date_published":"2026-08-13T18:56:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-hongjing-ehr-sql-injection/","summary":"Hongjing e-HR contains an unauthenticated SQL injection and path traversal vulnerability (CVE-2024-58374) allowing attackers to bypass authentication and exfiltrate database contents via the getSdutyTree servlet.","title":"Unauthenticated SQL Injection and Authentication Bypass in Hongjing e-HR","url":"https://feed.craftedsignal.io/briefs/2026-08-hongjing-ehr-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Hongjing","version":"https://jsonfeed.org/version/1.1"}