CVE-2026-108684
Received Received - Intake

SQL Injection in Jeewms Autocomplete Data Handler

Vulnerability report for CVE-2026-108684, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulDB

Description

A vulnerability was detected in erzhongxmu Jeewms up to 3.7. This affects the function getTreeData of the file src/main/java/com/jeecg/demo/controller/JeecgFormDemoController.java of the component Autocomplete Data Handler. Performing a manipulation of the argument searchVal results in sql injection. The attack can be initiated remotely. The patch is named 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0. It is recommended to apply a patch to fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
erzhongxmu Jeewms 3.0
erzhongxmu Jeewms 3.1
erzhongxmu Jeewms 3.2
erzhongxmu Jeewms 3.3
erzhongxmu Jeewms 3.4
erzhongxmu Jeewms 3.5
erzhongxmu Jeewms 3.6
erzhongxmu Jeewms 3.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a SQL injection flaw in the JeeWMS software up to version 3.7. It exists in the getTreeData function of the JeecgFormDemoController.java file. The issue allows attackers to manipulate the searchVal argument to inject malicious SQL code into queries. The vulnerability arises because user input is directly concatenated into SQL query strings without proper sanitization.

Detection Guidance

To detect this SQL injection vulnerability in JeeWMS, inspect the JeecgFormDemoController.getAutocompleteData method for direct SQL query construction using user input like searchVal. Check if queries are built via string concatenation rather than parameterized queries.

Impact Analysis

This vulnerability can allow remote attackers to execute arbitrary SQL commands on the database. This could lead to unauthorized data access, data manipulation, or deletion. Attackers might extract sensitive information, modify records, or even take control of the database server. The impact depends on the database permissions and the data stored.

Compliance Impact

This vulnerability can lead to non-compliance with GDPR and HIPAA. GDPR requires protection of personal data, and a SQL injection could expose such data. HIPAA mandates safeguards for protected health information; a breach via SQL injection would violate these requirements. Organizations may face fines and legal consequences for failing to protect sensitive data.

Mitigation Strategies

Apply the patch from commit 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0 which replaces direct SQL query construction with parameterized queries. Update the hql string to use placeholders and pass user input as parameters to systemService.findHql.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108684. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart