PT-2025-30167 · Thinkgem · Jeesite

Zast.Ai

·

Published

2025-07-20

·

Updated

2025-11-11

·

CVE-2025-7865

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions thinkgem JeeSite versions up to 5.12.0
Description A vulnerability exists in thinkgem JeeSite up to version 5.12.0 related to cross-site scripting. The issue resides in the xssFilter function within the src/main/java/com/jeesite/common/codec/EncodeUtils.java file of the XSS Filter component. Manipulation of the text argument can lead to the execution of malicious scripts. The attack can be initiated remotely. The exploit for this issue has been publicly disclosed.
Recommendations Apply the patch identified as 3585737d21fe490ff6948d913fcbd8d99c41fc08 to resolve this issue.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-7865

Affected Products

Jeesite