鸿景 e-HR 系统中存在一个未认证的 SQL 注入漏洞,位于 servlet 端点。攻击者可通过在请求 URI 中提供路径遍历序列,绕过 认证过滤器,从而访问受保护资源。由于 参数未经过适当过滤,攻击者可向其注入基于 UNION 的 SQL 载荷,进而查询底层 Microsoft SQL Server 数据库,获取包括用户凭据在内的敏感数据。该漏洞的利用迹象首次由 Shadowserver 基金会于 2024 年 7 月 30 日(UTC 时间)观察到。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hongjing Century | e-HR | |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hongjing Century | e-HR | 0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet