A vulnerability was found in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. It has been rated as critical. This vulnerability affects unknown code of the file /base-boot/jmreport/testConnection of the component JimuReport test-connection Endpoint. Performing a manipulation of the argument dbType/dbDriver/dbUrl/dbUsername/dbPassword results in injection.

This vulnerability is known as CVE-2026-11457. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.

The vendor was contacted early about this disclosure but did not respond in any way.