Description
A security flaw has been discovered in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This vulnerability affects unknown code of the file /base-boot/jmreport/testConnection of the component JimuReport test-connection Endpoint. Performing a manipulation of the argument dbType/dbDriver/dbUrl/dbUsername/dbPassword results in injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-06-07
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The issue involves the JimuReport test‑connection endpoint of erzhongxmu JeeWMS. By altering the parameters dbType, dbDriver, dbUrl, dbUsername, and dbPassword, an attacker can inject data that is used in database operations. The vendor’s description states that this injection can be performed remotely, which is inferred to allow malicious code or query manipulation. Such injection could compromise database integrity or confidentiality if the input is processed by the database layer.

Affected Systems

The vulnerability affects all rolling‑release builds of erzhongxmu JeeWMS that contain the /base‑boot/jmreport/testConnection component. No specific versions are listed, so any installation that has not received an undisclosed fix may be at risk.

Risk and Exploitability

The CVSS score of 6.9 reflects a moderate severity level. EPSS data is unavailable, so the exact exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be remote HTTP requests to the testConnection endpoint, with a known public exploit available. The risk includes potential compromise of database operations if the injected data is executed.

Generated by OpenCVE AI on June 7, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest JeeWMS release that contains the fix for the testConnection injection flaw as soon as it becomes available.
  • Restrict external access to the /base-boot/jmreport/testConnection endpoint, allowing only trusted networks or authenticated users to reach it.
  • Implement application‑level input validation on dbType, dbDriver, dbUrl, dbUsername, and dbPassword to reject or sanitize special or executable characters.

Generated by OpenCVE AI on June 7, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 07 Jun 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Erzhongxmu
Erzhongxmu jeewms
Vendors & Products Erzhongxmu
Erzhongxmu jeewms

Sun, 07 Jun 2026 08:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This vulnerability affects unknown code of the file /base-boot/jmreport/testConnection of the component JimuReport test-connection Endpoint. Performing a manipulation of the argument dbType/dbDriver/dbUrl/dbUsername/dbPassword results in injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
Title erzhongxmu JeeWMS JimuReport test-connection Endpoint testConnection injection
First Time appeared Jeewms
Jeewms jeewms
Weaknesses CWE-707
CWE-74
CPEs cpe:2.3:a:jeewms:jeewms:*:*:*:*:*:*:*:*
Vendors & Products Jeewms
Jeewms jeewms
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-07T07:45:07.255Z

Reserved: 2026-06-06T16:02:03.321Z

Link: CVE-2026-11457

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-07T09:16:21.843

Modified: 2026-06-07T09:16:21.843

Link: CVE-2026-11457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-07T10:30:05Z

Weaknesses