SQL Injection Vulnerability in JeeWMS Remote Access
CVE-2025-5384
5.3MEDIUM
What is CVE-2025-5384?
A vulnerability exists in JeeWMS affecting the CgAutoListController function accessible via the /cgAutoListController.do?datagrid endpoint. This flaw allows for SQL injection attacks that can be exploited remotely, potentially compromising data integrity. Due to the product's rolling release strategy, specific version information for updates or further mitigations is not disclosed.
Affected Version(s)
JeeWMS 20250504