PT-2025-30167 · Thinkgem · Jeesite
Zast.Ai
·
Published
2025-07-20
·
Updated
2025-11-11
·
CVE-2025-7865
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
thinkgem JeeSite versions up to 5.12.0
Description
A vulnerability exists in thinkgem JeeSite up to version 5.12.0 related to cross-site scripting. The issue resides in the
xssFilter function within the src/main/java/com/jeesite/common/codec/EncodeUtils.java file of the XSS Filter component. Manipulation of the text argument can lead to the execution of malicious scripts. The attack can be initiated remotely. The exploit for this issue has been publicly disclosed.Recommendations
Apply the patch identified as 3585737d21fe490ff6948d913fcbd8d99c41fc08 to resolve this issue.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jeesite