A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file src/main/java/com/jeecg/demo/controller/JeecgListDemoController.java. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Project Subscriptions

Vendors Products
Huayi-tec Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 26 Feb 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Huayi-tec
Huayi-tec jeewms
CPEs cpe:2.3:a:huayi-tec:jeewms:*:*:*:*:*:*:*:*
Vendors & Products Huayi-tec
Huayi-tec jeewms

Wed, 25 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file src/main/java/com/jeecg/demo/controller/JeecgListDemoController.java. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title erzhongxmu JEEWMS JeecgListDemoController.java doAdd cross site scripting
First Time appeared Jeewms
Jeewms jeewms
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:jeewms:jeewms:*:*:*:*:*:*:*:*
Vendors & Products Jeewms
Jeewms jeewms
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-25T15:28:13.880Z

Reserved: 2026-02-23T14:05:23.655Z

Link: CVE-2026-3028

cve-icon Vulnrichment

Updated: 2026-02-25T15:27:59.326Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-23T22:16:25.743

Modified: 2026-02-26T03:05:29.523

Link: CVE-2026-3028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-24T09:54:45Z

Weaknesses