PatchSiren cyber security CVE debrief
CVE-2024-58374 Hongjing Century CVE debrief
CVE-2024-58374 is a high-severity unauthenticated SQL injection vulnerability in the Hongjing e-HR system, specifically in the getSdutyTree servlet endpoint. This vulnerability allows remote attackers to bypass authentication and access sensitive database contents, including user credentials, by injecting UNION-based SQL payloads through the unsanitized codeitemid parameter.
- Vendor
- Hongjing Century
- Product
- e-HR
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for the Hongjing e-HR system, security teams, and IT administrators should be aware of this vulnerability and take necessary actions to prevent exploitation. This includes verifying the presence of the system in their environment, assessing exposure, applying patches or mitigations, and monitoring for suspicious activity. Additionally, operators and platform administrators should prioritize verifying the presence of this vulnerability
Why it matters
CVE-2024-58374 is a high-severity SQL injection vulnerability in Hongjing e-HR that allows unauthenticated access to sensitive database contents. Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations to prevent exploitation.
- Verify the presence of the Hongjing e-HR system in your environment and assess exposure to this vulnerability.
- Apply patches or mitigations to prevent exploitation of the SQL injection vulnerability.
- Monitor for suspicious activity related to the getSdutyTree servlet endpoint.
Technical summary
The Hongjing e-HR system contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint. This vulnerability allows remote attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying Microsoft SQL Server query to retrieve sensitive database contents, including user credentials.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations to prevent exploitation.
Recommended defensive actions
- Verify the presence of the Hongjing e-HR system in your environment and assess exposure to this vulnerability.
- Review and apply patches or mitigations to prevent exploitation of the SQL injection vulnerability.
- Monitor for suspicious activity related to the getSdutyTree servlet endpoint.
- Consider implementing additional security controls to protect against SQL injection attacks.
- Track exceptions and retest remediated assets.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The vulnerability was first observed by the Shadowserver Foundation on 2024-07-30 (UTC). The CVE record and NVD entry provide details on the vulnerability, but the vendor and affected versions are not clearly identified.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-58374 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-58374
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-58374 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-58374
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cn-sec.com/archives/2926383.html
-
Source reference
Unverified legacy reference
URL: https://www.ddpoc.com/DVB-2024-7391.html
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/hongjing-e-hr-unauthenticated-sql-injection-via-getsdutytree
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.