Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in erzhongxmu Jeewms up to 3.7. This affects the function getTreeData of the file src/main/java/com/jeecg/demo/controller/JeecgFormDemoController.java of the component Autocomplete Data Handler. Performing a manipulation of the argument searchVal results in sql injection. The attack can be initiated remotely. The patch is named 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0. It is recommended to apply a patch to fix this issue. | |
| Title | erzhongxmu Jeewms Autocomplete Data JeecgFormDemoController.java getTreeData sql injection | |
| First Time appeared |
Jeewms
Jeewms jeewms |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:jeewms:jeewms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeewms
Jeewms jeewms |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-11T14:45:14.792Z
Reserved: 2026-10-10T21:29:15.771Z
Link: CVE-2026-108684
No data.
Status : Received
Published: 2026-10-11T15:16:52.947
Modified: 2026-10-11T15:16:52.947
Link: CVE-2026-108684
No data.
OpenCVE Enrichment
Updated: 2026-10-11T16:30:17Z