VYPR

Hongjing e-HR

by Vulncheck

CVEs (1)

  • CVE-2023-54399CriSep 18, 2026
    risk 0.64cvss 9.8epss

    Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticated remote attacker can supply a crafted…