PT-2025-30166 · Thinkgem · Jeesite

·

CVE-2025-7864

·

Published

2025-07-20

·

Updated

2025-11-11

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions thinkgem JeeSite versions up to 5.12.0
Description A critical issue exists in thinkgem JeeSite that allows for unrestricted file uploads. The Upload function within the file src/main/java/com/jeesite/modules/file/web/FileUploadController.java is affected. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations Apply a patch with identifier 3585737d21fe490ff6948d913fcbd8d99c41fc08 to resolve this issue.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7864

Affected Products

Jeesite