CVE-2026-108684
Description
A vulnerability was detected in erzhongxmu Jeewms up to 3.7. This affects the function getTreeData of the file src/main/java/com/jeecg/demo/controller/JeecgFormDemoController.java of the component Autocomplete Data Handler. Performing a manipulation of the argument searchVal results in sql injection. The attack can be initiated remotely. The patch is named 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0. It is recommended to apply a patch to fix this issue.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/Lib0gus/JeeWMS/security/advisories/GHSA-mc7c-w398-v7xp
- https://github.com/erzhongxmu/JeeWMS/
- https://github.com/erzhongxmu/JeeWMS/commit/6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0
- https://github.com/erzhongxmu/JeeWMS/pull/4
- https://vuldb.com/cve/CVE-2026-108684
- https://vuldb.com/submit/959244
- https://vuldb.com/vuln/416392
- https://vuldb.com/vuln/416392/cti
CWEs
CWE-74 CWE-89
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.