PatchSiren

Hongjing Century CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Hongjing Century CVE published 2026-08-13

CVE-2024-58374

CVE-2024-58374 is a high-severity unauthenticated SQL injection vulnerability in the Hongjing e-HR system, specifically in the getSdutyTree servlet endpoint. This vulnerability allows remote attackers to bypass authentication and access sensitive database contents, including user credentials, by injecting UNION-based SQL payloads through the unsanitized codeitemid parameter.