CVE-2023-54399

CVE-2023-54399 published: Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker ...

View full NVD advisory → ← Back to CVE watch