RULE(RULE ID:338310)

Rule General Information
Release Date: 2024-08-13
Rule Name: Hjsoft eHR ajaxService SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: The Hjsoft eHR is a professional human resources management software designed to help enterprises efficiently handle employee information, compensation and benefits, recruitment and training, and other human resources related affairs. Its ajaxService has SQL injection vulnerabilities that attackers can exploit to insert malicious SQL code into database queries, which can lead to data leaks, data corruption, service interruptions, and even complete control of the entire database system, posing a serious threat to enterprise data security.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.