CVE-2024-58374 HIGH

CVE-2024-58374: Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree

Vendor Hongjing Century
Product e-HR
Weakness CWE-89 · SQLi
Published August 13, 2026
Last update August 13, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying Microsoft SQL Server query to retrieve sensitive database contents including user credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30 (UTC).

Key dates

02Disclosure timeline

August 13, 2026 CVE published
August 13, 2026 Record updated

Related vulnerabilities

04Related CVE