A vulnerability was found in JeeWMS up to 20250504. It has been rated as critical. This issue affects the function transEditor of the file /cgformTransController.do?transEditor. The manipulation leads to sql injection. The attack may be initiated remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
References
Link | Resource |
---|---|
https://gitee.com/erzhongxmu/JEEWMS/issues/IC5FNV | Issue Tracking |
https://vuldb.com/?ctiid.310679 | Permissions Required VDB Entry |
https://vuldb.com/?id.310679 | Third Party Advisory VDB Entry |
Configurations
History
11 Sep 2025, 20:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitee.com/erzhongxmu/JEEWMS/issues/IC5FNV - Issue Tracking | |
References | () https://vuldb.com/?ctiid.310679 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.310679 - Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:huayi-tec:jeewms:*:*:*:*:*:*:*:* | |
First Time |
Huayi-tec
Huayi-tec jeewms |
02 Jun 2025, 17:32
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-31 17:15
Updated : 2025-09-11 20:43
NVD link : CVE-2025-5386
Mitre link : CVE-2025-5386
CVE.ORG link : CVE-2025-5386
JSON object : View
Products Affected
huayi-tec
- jeewms