Description
Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker can supply a crafted UNION SELECT payload to read arbitrary database content, including credential tables such as operuser. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
Published: 2026-09-18
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Credential Theft
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a classic SQL injection flaw in the /servlet/codesettree endpoint of Hongjing e-HR software versions older than 8.2. The application forwards the categories query parameter directly into a database query after stripping HRMS-encoding, creating a path for arbitrary SQL commands. An attacker can thus craft a UNION SELECT payload that reveals any database contents, including credential tables such as operuser.

Affected Systems

Affected systems are deployments of Hongjing e-HR prior to upgrade to version 8.2. No additional version granularity is specified, so any instance running a pre‑8.2 build is susceptible.

Risk and Exploitability

The CVSS score of 9.3 highlights the shockingly severe impact of this flaw, while the EPSS score is presently unavailable, leaving uncertainty about current exploitation prevalence. The vulnerability is listed as not in KEV, suggesting no known exploitation yet. Attackers can reach the vulnerable endpoint via an unauthenticated HTTP request from any remote host, making exploitation trivial for anyone with internet access to the application. Because the flaw permits reading confidential data, the potential damage is considerable.

Generated by OpenCVE AI on September 19, 2026 at 10:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Hongjing e-HR to version 8.2 or later to eliminate the vulnerable endpoint.
  • Restrict access to /servlet/codesettree, allowing only trusted internal network traffic.
  • Implement strict input validation and parameterized queries for the categories parameter to prevent injection.

Generated by OpenCVE AI on September 19, 2026 at 10:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Hongjing
Hongjing e-hr
Vendors & Products Hongjing
Hongjing e-hr

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker can supply a crafted UNION SELECT payload to read arbitrary database content, including credential tables such as operuser. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
Title Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:48:30.092Z

Reserved: 2026-09-17T18:24:19.897Z

Link: CVE-2023-54399

cve-icon Vulnrichment

Updated: 2026-09-21T15:48:04.174Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T19:16:40.757

Modified: 2026-09-22T20:53:07.383

Link: CVE-2023-54399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:55Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')