CVE-2024-58352CWE-564

Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do

High · published July 2, 2026

CVSS v4.0
8.7
EPSS
1%
Percentile
57.2
In the wild
Unconfirmed
What it is

Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitrary Hibernate entity classes by injecting malicious HQL syntax into the uid POST parameter of the wechatLoginHelper.do endpoint. Attackers can exploit the lack of input sanitization in the string-concatenated filter expression passed to the Hibernate findList() call to extract sensitive data such as administrator password hashes and, with sufficient database privileges, perform file-write operations enabling remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-11 (UTC).

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00896 · 57.2th percentile
Weakness
CWE-564 · SQL Injection: Hibernate
Published
2026-07-02T17:05Z
EPSS history
Timeline
  • 02 JUL 17:05Z
    Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do
    cvelistv5