NVD HIGH: CVE-2024-58374 — Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the get...
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying
CVE-2024-58374