'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-07-08 | |
| Rule Name: | Hongjing HCM Local File Inclusion Vulnerability | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | Hongjing HCM is a digital and intelligent human resources and talent management product developed by Beijing Hongjing Century Software Co., Ltd. Hongjing HCM contains a local file inclusion vulnerability. Attackers can exploit this flaw by crafting special inputs, taking advantage of the application's insufficient validation of file path parameters, thereby forcing the system to read arbitrary files from the server's local file system. | |
| Impact: | When the file operation function in the application that does not filter the file path effectively, an attacker can import the path of a file which contains malicious code, causing a file inclusion vulnerability and executing malicious code. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | ||
| Solutions |
|---|
| Please contact the software vendor to update the software patch. |