SQL Injection Vulnerability in erzhongxmu Jeewms Product
CVE-2026-108684

5.3MEDIUM

Key Information:

Vendor

Erzhongxmu

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108684?

A vulnerability in erzhongxmu's Jeewms product allows for remote SQL injection through the getTreeData function in the Autocomplete Data Handler. By manipulating the searchVal argument, attackers can execute unauthorized SQL commands. This issue affects Jeewms version 3.7 and requires immediate action through the application of the provided patch (commit 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0) to mitigate potential threats.

Affected Version(s)

Jeewms 3.0

Jeewms 3.1

Jeewms 3.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lib0gus (VulDB User)
.