PT-2025-30166 · Thinkgem · Jeesite

Zast.Ai

·

Published

2025-07-20

·

Updated

2025-11-11

·

CVE-2025-7864

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions thinkgem JeeSite versions up to 5.12.0
Description A critical issue exists in thinkgem JeeSite that allows for unrestricted file uploads. The Upload function within the file src/main/java/com/jeesite/modules/file/web/FileUploadController.java is affected. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations Apply a patch with identifier 3585737d21fe490ff6948d913fcbd8d99c41fc08 to resolve this issue.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-7864

Affected Products

Jeesite