Impact
A vulnerability in Jeewms allows an attacker to inject arbitrary SQL through the searchVal parameter used by the getTreeData function in JeecgFormDemoController. This unsanitized input leads to potential unauthorized read and modify operations on the database, compromising confidentiality and integrity of stored data according to CWE-74 and CWE-89.
Affected Systems
The affected product is erzhongxmu Jeewms, versions up to and including 3.7. Any deployment of these versions is susceptible if the vulnerable endpoint is reachable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and while no EPSS score is available and the vulnerability is not listed in CISA KEV, the ability to trigger the injection remotely means the exploit can be launched over a network. Organizations should consider the risk moderate to high, especially if the application is exposed to untrusted traffic.
OpenCVE Enrichment