← Back to search

CVE-2023-54399

9.8 CRITICAL

Published 2026-09-18 · Updated 2026-09-22

AI risk analysis

Summary
This vulnerability allows an unauthenticated attacker to inject SQL queries and read arbitrary database content, including sensitive credential tables.
Exploitability
Exploitation is relatively straightforward as the vulnerability requires no authentication and can be triggered via a crafted URL parameter.
Blast radius
If exploited, the attacker could gain access to sensitive data such as credentials, potentially leading to further attacks or data breaches.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Hongjing e-HR 8.2 or later.
rcesql-injectionwebunauth

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker can supply a crafted UNION SELECT payload to read arbitrary database content, including credential tables such as operuser. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.