Impact
The vulnerability is a classic SQL injection flaw in the /servlet/codesettree endpoint of Hongjing e-HR software versions older than 8.2. The application forwards the categories query parameter directly into a database query after stripping HRMS-encoding, creating a path for arbitrary SQL commands. An attacker can thus craft a UNION SELECT payload that reveals any database contents, including credential tables such as operuser.
Affected Systems
Affected systems are deployments of Hongjing e-HR prior to upgrade to version 8.2. No additional version granularity is specified, so any instance running a pre‑8.2 build is susceptible.
Risk and Exploitability
The CVSS score of 9.3 highlights the shockingly severe impact of this flaw, while the EPSS score is presently unavailable, leaving uncertainty about current exploitation prevalence. The vulnerability is listed as not in KEV, suggesting no known exploitation yet. Attackers can reach the vulnerable endpoint via an unauthenticated HTTP request from any remote host, making exploitation trivial for anyone with internet access to the application. Because the flaw permits reading confidential data, the potential damage is considerable.
OpenCVE Enrichment