CVE-2026-108778 | erzhongxmu JEEWMS up to 2026.09.27-W39 Inbound Quality Check Pda Interface WmInQmIController.java WmInQmIController.list searchstr sql injection

SecurityVulns

A vulnerability, which was classified as critical, has been found in erzhongxmu JEEWMS up to 2026.09.27-W39. This impacts the function WmInQmIController.list of the file src/main/java/com/zzjee/wm/controller/WmInQmIController.java of the component Inbound Quality Check Pda Interface. This manipulation of the argument searchstr causes sql injection.

This vulnerability is tracked as CVE-2026-108778. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More