PT-2025-29981 · Thinkgem · Jeesite

Zast.Ai

·

Published

2025-07-17

·

Updated

2025-11-11

·

CVE-2025-7763

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions thinkgem JeeSite versions up to 5.12.0
Description A problematic vulnerability exists in thinkgem JeeSite. The select function within the src/main/java/com/jeesite/modules/cms/web/SiteController.java file of the Site Controller component is affected. Manipulation of the redirect argument results in an open redirect. The attack can be launched remotely, and the exploit has been publicly disclosed. Multiple endpoints are affected.
Recommendations Apply patch 3d06b8d009d0267f0255acc87ea19d29d07cedc3 to resolve this issue.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7763

Affected Products

Jeesite