CVE-2026-108782 | erzhongxmu JEEWMS up to 2026.09.27-W39 Autocomplete CommonServiceImpl.java CommonServiceImpl.getAutoList trem/searchField/entityName sql injection
A vulnerability was found in erzhongxmu JEEWMS up to 2026.09.27-W39 and classified as critical. Affected by this issue is the function CommonServiceImpl.getAutoList of the file src/main/java/org/jeecgframework/core/common/service/impl/CommonServiceImpl.java of the component Autocomplete Handler. Executing a manipulation of the argument trem/searchField/entityName can lead to sql injection.
This vulnerability is registered as CVE-2026-108782. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More