CVE-2026-108777 | erzhongxmu JEEWMS up to 2026.09.27-W39 WvGiController.java WvGiController.list searchstr sql injection
A vulnerability classified as critical was found in erzhongxmu JEEWMS up to 2026.09.27-W39. This affects the function WvGiController.list of the file src/main/java/com/zzjee/wmapi/controller/WvGiController.java. The manipulation of the argument searchstr results in sql injection.
This vulnerability is identified as CVE-2026-108777. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More