S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 18, 2025

CVE-2023-6655 Scanner

CVE-2023-6655 Scanner - SQL Injection vulnerability in Hongjing e-HR

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-6655
7.3
CVSShigh
Exploitable remotely over the internet · no authentication required.

A vulnerability, which was classified as critical, has been found in Hongjing e-HR 2020. Affected by this issue is some unknown functionality of the file /w_selfservice/oauthservlet/%2e./.%2e/general/inform/org/loadhistroyorgtree of the component Login Interface. The manipulation of the argument parentid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247358 is the identifier assigned to this vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
e-HRby Hongjing
2020
Updated Sep 10, 2026View on NVD →
Detail

The Hongjing e-HR system is a comprehensive Human Resource Management System (HRMS) used by organizations to manage their employee information and related processes. It is primarily deployed in enterprise environments where there is a need to handle large amounts of HR data. The software facilitates various HR functions like payroll, recruitment, attendance, and training management. Companies use it to ensure efficient HR operations by providing a centralized platform for managing employee data and HR workflows. It is popular in regions where Hongjing software solutions have a strong user base. The system can be accessed over a network, allowing remote management of human resources activities.

SQL Injection is a type of vulnerability that allows attackers to interact with a backend database through maliciously crafted SQL queries. It targets the database layer of an application, potentially giving attackers unauthorized access to sensitive data. In the context of Hongjing e-HR, SQL Injection could compromise information stored in the system, affecting data integrity and confidentiality. The vulnerability is particularly concerning as it doesn't require user authentication, meaning attackers can exploit it remotely without prior access. SQL Injection vulnerabilities like this are commonly targeted by cybercriminals due to the high-value data they expose.

The specific vulnerability in Hongjing e-HR involves the 'parentid' parameter in the Login Interface component, which is manipulated through crafted SQL queries. By injecting specific SQL commands, attackers can force the database to execute unintended actions. The endpoint /w_selfservice/oauthservlet/%2e./.%2e/general/inform/org/loadhistroyorgtree is exploited by modifying the 'parentid' argument to include SQL statements that delay the application's response, confirming the vulnerability's presence. Such technical details are critical as they give security professionals the specifics needed to test and remediate vulnerabilities.

If exploited, the SQL Injection vulnerability in Hongjing e-HR could lead to unauthorized disclosure of sensitive HR data, including personal and financial information of employees. It could also allow attackers to alter or delete database entries, causing significant disruption to HR operations. Beyond data theft, the abuse of SQL Injection might enable attackers to compromise the entire application, escalating privileges, or launching further attacks from a foothold within the network. The potential damage to an organization's data and reputation makes addressing such vulnerabilities imperative.

REFERENCES

Solution Advice
  • Implement prepared statements or parameterized queries to prevent SQL Injection attacks.
  • Regularly update and patch Hongjing e-HR software to apply security fixes.
  • Conduct thorough code reviews focusing on input validation to prevent injection flaws.
  • Employ web application firewalls and intrusion detection systems to monitor for exploit activities.
  • Educate developers on security best practices to minimize vulnerabilities in development stages.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-6655 Scanner - SQL Injection vulnerability in Hongjing e-HR | S4E