CVE-2026-3028

A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file src/main/java/com/jeecg/demo/controller/JeecgListDemoController.java. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.347384 Permissions Required VDB Entry
https://vuldb.com/?id.347384 Third Party Advisory VDB Entry
https://vuldb.com/?submit.756527 Third Party Advisory VDB Entry
https://www.notion.so/JEEWMS-Stored-Cross-Site-Scripting-XSS-in-SysModule-304ea92a3c418099bed7f1e0bca12d83 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:huayi-tec:jeewms:*:*:*:*:*:*:*:*

History

26 Feb 2026, 03:05

Type Values Removed Values Added
References () https://vuldb.com/?ctiid.347384 - () https://vuldb.com/?ctiid.347384 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.347384 - () https://vuldb.com/?id.347384 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.756527 - () https://vuldb.com/?submit.756527 - Third Party Advisory, VDB Entry
References () https://www.notion.so/JEEWMS-Stored-Cross-Site-Scripting-XSS-in-SysModule-304ea92a3c418099bed7f1e0bca12d83 - () https://www.notion.so/JEEWMS-Stored-Cross-Site-Scripting-XSS-in-SysModule-304ea92a3c418099bed7f1e0bca12d83 - Exploit, Third Party Advisory
Summary
  • (es) Se encontró una vulnerabilidad en erzhongxmu JEEWMS hasta la versión 3.7. Esta vulnerabilidad afecta la función doAdd del archivo src/main/java/com/jeecg/demo/controller/JeecgListDemoController.java. Manipular el argumento Name causa un cross-site scripting. El ataque puede ser iniciado en remoto. El exploit ha sido divulgado públicamente y puede ser utilizado. El proveedor fue contactado con antelación sobre esta divulgación, pero no respondió de ninguna manera.
First Time Huayi-tec jeewms
Huayi-tec
CPE cpe:2.3:a:huayi-tec:jeewms:*:*:*:*:*:*:*:*

23 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 22:16

Updated : 2026-02-26 03:05


NVD link : CVE-2026-3028

Mitre link : CVE-2026-3028

CVE.ORG link : CVE-2026-3028


JSON object : View

Products Affected

huayi-tec

  • jeewms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')