SQL Injection Vulnerability in erzhongxmu Jeewms Product
CVE-2026-108684
5.3MEDIUM
What is CVE-2026-108684?
A vulnerability in erzhongxmu's Jeewms product allows for remote SQL injection through the getTreeData function in the Autocomplete Data Handler. By manipulating the searchVal argument, attackers can execute unauthorized SQL commands. This issue affects Jeewms version 3.7 and requires immediate action through the application of the provided patch (commit 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0) to mitigate potential threats.
Affected Version(s)
Jeewms 3.0
Jeewms 3.1
Jeewms 3.2
