JeeWMS generateController.do dogenerate sql injection

CVE Details

Basic Information

Title JeeWMS generateController.do dogenerate sql injection
Type cve
Published 2025-05-31T18:00:09.009Z
Last Seen

Product Information

Vendor n/a
Product JeeWMS
Version 20250504

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A critical SQL injection vulnerability exists in JeeWMS up to version 20250504, specifically in the `dogenerate` function of `/generateController.do`. This allows remote attackers to execute arbitrary SQL commands. The product uses rolling releases, so specific affected versions are not detailed.
AI Severity High
Vendor JeeWMS
Product JeeWMS
Affected Version up to 20250504

Additional Information

CVE List
CWE List CWE-89, CWE-74
Bulletin Family
Source Data n/a JeeWMS 20250504

Source Information

Source Data n/a JeeWMS 20250504
Source Link

Description

A vulnerability classified as critical was found in JeeWMS up to 20250504. Affected by this vulnerability is the function dogenerate of the file /generateController.do?dogenerate. The manipulation leads to sql injection. The attack can be launched remotely. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.

CVSS Score Summary

Base Score: 5.3 (MEDIUM)

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.