Description
A vulnerability was detected in erzhongxmu Jeewms up to 3.7. This affects the function getTreeData of the file src/main/java/com/jeecg/demo/controller/JeecgFormDemoController.java of the component Autocomplete Data Handler. Performing a manipulation of the argument searchVal results in sql injection. The attack can be initiated remotely. The patch is named 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0. It is recommended to apply a patch to fix this issue.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: SQL injection that can be performed remotely
Action: Apply Patch
AI Analysis

Impact

A vulnerability in Jeewms allows an attacker to inject arbitrary SQL through the searchVal parameter used by the getTreeData function in JeecgFormDemoController. This unsanitized input leads to potential unauthorized read and modify operations on the database, compromising confidentiality and integrity of stored data according to CWE-74 and CWE-89.

Affected Systems

The affected product is erzhongxmu Jeewms, versions up to and including 3.7. Any deployment of these versions is susceptible if the vulnerable endpoint is reachable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and while no EPSS score is available and the vulnerability is not listed in CISA KEV, the ability to trigger the injection remotely means the exploit can be launched over a network. Organizations should consider the risk moderate to high, especially if the application is exposed to untrusted traffic.

Generated by OpenCVE AI on October 11, 2026 at 16:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch identified by commit 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0 or upgrade Jeewms to a version newer than 3.7.
  • Ensure that the endpoint handling getTreeData is only accessible from trusted networks or protected by authentication and that the searchVal parameter is validated or properly encoded before SQL execution.
  • Monitor logs for anomalous database activity and conduct periodic vulnerability scans to confirm that the injection path is eliminated.

Generated by OpenCVE AI on October 11, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in erzhongxmu Jeewms up to 3.7. This affects the function getTreeData of the file src/main/java/com/jeecg/demo/controller/JeecgFormDemoController.java of the component Autocomplete Data Handler. Performing a manipulation of the argument searchVal results in sql injection. The attack can be initiated remotely. The patch is named 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0. It is recommended to apply a patch to fix this issue.
Title erzhongxmu Jeewms Autocomplete Data JeecgFormDemoController.java getTreeData sql injection
First Time appeared Jeewms
Jeewms jeewms
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:jeewms:jeewms:*:*:*:*:*:*:*:*
Vendors & Products Jeewms
Jeewms jeewms
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-11T14:45:14.792Z

Reserved: 2026-10-10T21:29:15.771Z

Link: CVE-2026-108684

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T15:16:52.947

Modified: 2026-10-11T15:16:52.947

Link: CVE-2026-108684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T17:00:09Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')