PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-58374 Hongjing Century CVE debrief

CVE-2024-58374 is a high-severity unauthenticated SQL injection vulnerability in the Hongjing e-HR system, specifically in the getSdutyTree servlet endpoint. This vulnerability allows remote attackers to bypass authentication and access sensitive database contents, including user credentials, by injecting UNION-based SQL payloads through the unsanitized codeitemid parameter.

Vendor
Hongjing Century
Product
e-HR
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-09
Advisory published
2026-08-13
Advisory updated
2026-09-09

Who should care

Defenders responsible for the Hongjing e-HR system, security teams, and IT administrators should be aware of this vulnerability and take necessary actions to prevent exploitation. This includes verifying the presence of the system in their environment, assessing exposure, applying patches or mitigations, and monitoring for suspicious activity. Additionally, operators and platform administrators should prioritize verifying the presence of this vulnerability

Why it matters

CVE-2024-58374 is a high-severity SQL injection vulnerability in Hongjing e-HR that allows unauthenticated access to sensitive database contents. Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations to prevent exploitation.

  • Verify the presence of the Hongjing e-HR system in your environment and assess exposure to this vulnerability.
  • Apply patches or mitigations to prevent exploitation of the SQL injection vulnerability.
  • Monitor for suspicious activity related to the getSdutyTree servlet endpoint.

Technical summary

The Hongjing e-HR system contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint. This vulnerability allows remote attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying Microsoft SQL Server query to retrieve sensitive database contents, including user credentials.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations to prevent exploitation.

Recommended defensive actions

  • Verify the presence of the Hongjing e-HR system in your environment and assess exposure to this vulnerability.
  • Review and apply patches or mitigations to prevent exploitation of the SQL injection vulnerability.
  • Monitor for suspicious activity related to the getSdutyTree servlet endpoint.
  • Consider implementing additional security controls to protect against SQL injection attacks.
  • Track exceptions and retest remediated assets.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The vulnerability was first observed by the Shadowserver Foundation on 2024-07-30 (UTC). The CVE record and NVD entry provide details on the vulnerability, but the vendor and affected versions are not clearly identified.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-58374 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-58374

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-58374 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-58374

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.