← All Advisories

CVE-2024-58374

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2024-58374

Key Details

CVECVE-2024-58374
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-01
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsHongjing Century e-HR
Classified asCWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Hongjing Centurye-HR
SubsystemsGeneral OT
SectorsMultiple

What to Know

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying Microsoft SQL Server query to retrieve sensitive database contents including user credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30 (UTC). (NVD)

What to Do

Monitor Hongjing Century's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2024-58374
CVEhttps://www.cve.org/CVERecord?id=CVE-2024-58374