PT-2025-30165 · Thinkgem · Jeesite

Zast.Ai

·

Published

2025-07-20

·

Updated

2025-11-11

·

CVE-2025-7863

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions thinkgem JeeSite versions up to 5.12.0
Description An open redirect issue exists in the redirectUrl function located in the file src/main/java/com/jeesite/common/web/http/ServletUtils.java. The manipulation of the url argument can lead to an open redirect, allowing for remote exploitation.
Recommendations Apply the patch 3d06b8d009d0267f0255acc87ea19d29d07cedc3 to resolve the issue.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-7863

Affected Products

Jeesite