{"id":"CVE-2023-54399","published":"2026-09-18T19:16:40.757","lastModified":"2026-09-22T20:53:07.383","description":"Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker can supply a crafted UNION SELECT payload to read arbitrary database content, including credential tables such as operuser. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://cn-sec.com/archives/1861976.html","tags":[]},{"url":"https://www.cloudsek.com/blog/mozi-resurfaces-as-androxgh0st-botnet-unraveling-the-latest-exploitation-wave","tags":[]},{"url":"https://www.cnblogs.com/pursue-security/p/17704093.html","tags":[]},{"url":"https://www.cnvd.org.cn/flaw/show/CNVD-2023-08743","tags":[]},{"url":"https://www.vulncheck.com/advisories/hongjing-e-hr-sql-injection-via-servlet-codesettree","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows an unauthenticated attacker to inject SQL queries and read arbitrary database content, including sensitive credential tables.","exploitability":"Exploitation is relatively straightforward as the vulnerability requires no authentication and can be triggered via a crafted URL parameter.","blast_radius":"If exploited, the attacker could gain access to sensitive data such as credentials, potentially leading to further attacks or data breaches.","remediation":"Upgrade to Hongjing e-HR 8.2 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","sql-injection","web","unauth"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T09:01:37.990Z"}}