PT-2026-55264 · Landray · Landray Oa
CVE-2024-58352
·
Published
2026-07-02
·
Updated
2026-07-13
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Landray OA (affected versions not specified)
Description
An unauthenticated HQL injection exists, allowing attackers to query arbitrary Hibernate entity classes. This occurs due to insufficient input sanitization in the string-concatenated filter expression used in the
findList() function. Attackers can inject malicious HQL syntax into the uid parameter of the 'wechatLoginHelper.do' endpoint to extract sensitive data, including administrator password hashes. If the database has sufficient privileges, this can lead to file-write operations and remote code execution. HQL (Hibernate Query Language) is an object-oriented query language used to retrieve data from a database. Evidence of exploitation was first observed on 2024-03-11 (UTC).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
uid parameter in the 'wechatLoginHelper.do' endpoint until the issue is resolved.Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Landray Oa