Impact
The vulnerability is an unauthenticated SQL injection in Hongjing e‑HR's getSdutyTree servlet. By supplying a path traversal sequence, attackers bypass the oauthservlet authentication filter and inject UNION‑based payloads into the codeitemid parameter. The unsanitized input allows the attacker to read sensitive data from the Microsoft SQL Server, including user credentials. This could lead to credential theft, account takeover, and broader system compromise if those credentials are used elsewhere.
Affected Systems
Hongjing Century’s e‑HR product is affected. No specific version information is provided; therefore any installation of the e‑HR suite that includes the getSdutyTree endpoint may be vulnerable.
Risk and Exploitability
With a CVSS score of 8.7 the vulnerability is rated high severity. Exploitation can occur remotely without authentication, using a straightforward HTTP request. Although no EPSS score is available, the description shows that Shadowserver observed exploitation. The vulnerability is not listed in the CISA KEV catalog, but the lack of authentication makes it highly attractive to attackers. Successful exploitation grants read access to database contents, exposing credentials and sensitive business data.
OpenCVE Enrichment