JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 parameters in the /systemControl.do interface for attack.
References
| Link | Resource |
|---|---|
| https://gitee.com/erzhongxmu/JEEWMS | Product |
Configurations
History
18 Feb 2026, 16:24
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gitee.com/erzhongxmu/JEEWMS - Product | |
| First Time |
Huayi-tec jeewms
Huayi-tec |
|
| CPE | cpe:2.3:a:huayi-tec:jeewms:-:*:*:*:*:*:*:* |
11 Feb 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CWE | CWE-89 |
03 Feb 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-03 18:16
Updated : 2026-02-18 16:24
NVD link : CVE-2025-70311
Mitre link : CVE-2025-70311
CVE.ORG link : CVE-2025-70311
JSON object : View
Products Affected
huayi-tec
- jeewms
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
