VYPR

e-HR

by Hongjing

CVEs (2)

  • CVE-2024-58374HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet…

  • CVE-2023-6655HigDec 10, 2023
    risk 0.48cvss 7.3epss 0.04

    A vulnerability, which was classified as critical, has been found in Hongjing e-HR 2020. Affected by this issue is some unknown functionality of the file /w_selfservice/oauthservlet/%2e./.%2e/general/inform/org/loadhistroyorgtree of the component Login Interface. The…