Sceawere
Vulnerability Detail
CVE-2026-108684UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Jeewms SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 3h ago
- Vendor
- erzhongxmu
- Product
- Jeewms
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in erzhongxmu Jeewms up to 3.7. This affects the function getTreeData of the file src/main/java/com/jeecg/demo/controller/JeecgFormDemoController.java of the component Autocomplete Data Handler. Performing a manipulation of the argument searchVal results in sql injection. The attack can be initiated remotely. The patch is named 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0. It is recommended to apply a patch to fix this issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-11T15:16:52.947Z",
"pubdate": "2026-10-11T15:16:52.947Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified in the Autocomplete Data Handler component of erzhongxmu Jeewms, specifically impacting versions up to 3.7.\nThe vulnerability originates from improper neutralization of special elements used in an SQL command within the getTreeData function.\nAn unauthenticated, remote attacker can exploit this flaw by supplying malicious input via the searchVal parameter.\nSuccessful exploitation allows the attacker to execute arbitrary SQL commands against the underlying database, potentially leading to unauthorized data disclosure, modification, or complete database compromise.\nGiven that the application is remotely accessible and does not require pre-existing authentication for this specific entry point, the risk to the system's confidentiality, integrity, and availability is considered high.\nImmediate application of the provided security patch is necessary to mitigate this risk.",
"technicalDetails": "The vulnerability is located in the file src/main/java/com/jeecg/demo/controller/JeecgFormDemoController.java, within the getTreeData function of the Autocomplete Data Handler.\nThe root cause of this vulnerability is the insecure handling of the searchVal request parameter. The application fails to properly sanitize, escape, or parameterize user-supplied input before incorporating it directly into a dynamic SQL query string.\nIn a typical attack flow, an adversary submits a crafted HTTP request to the vulnerable endpoint associated with the getTreeData function. The searchVal argument is populated with malicious SQL syntax rather than expected search criteria.\nBecause the input is concatenated directly into the backend SQL query, the database interpreter executes the injected malicious SQL commands within the context of the application's database user permissions.\nThis allows for various exploitation techniques, including tautology-based bypasses, UNION-based data extraction, or time-based blind SQL injection, depending on the database configuration and the specific implementation of the query.\nThis vulnerability is classified as a remote SQL injection, meaning no local access or prior authentication is required to initiate the attack, significantly increasing the potential attack surface.\nThe exploitation of this flaw can have severe post-exploitation impacts, including the unauthorized dumping of sensitive tables, modification of existing records, or in some configurations, the execution of administrative commands at the database level, which may further facilitate lateral movement or persistence within the environment.\nThe vulnerability affects all versions of erzhongxmu Jeewms up to 3.7. Remediation requires updating the codebase to align with the logic provided in patch 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0."
}