Impact
The issue involves the JimuReport test‑connection endpoint of erzhongxmu JeeWMS. By altering the parameters dbType, dbDriver, dbUrl, dbUsername, and dbPassword, an attacker can inject data that is used in database operations. The vendor’s description states that this injection can be performed remotely, which is inferred to allow malicious code or query manipulation. Such injection could compromise database integrity or confidentiality if the input is processed by the database layer.
Affected Systems
The vulnerability affects all rolling‑release builds of erzhongxmu JeeWMS that contain the /base‑boot/jmreport/testConnection component. No specific versions are listed, so any installation that has not received an undisclosed fix may be at risk.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity level. EPSS data is unavailable, so the exact exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be remote HTTP requests to the testConnection endpoint, with a known public exploit available. The risk includes potential compromise of database operations if the injected data is executed.
OpenCVE Enrichment