CVE-2025-7763 Information
Description
A vulnerability which was classified as problematic was found in thinkgem JeeSite up to 5.12.0. Affected is an unknown function of the component Site Controller/SSO. The manipulation leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 3d06b8d009d0267f0255acc87ea19d29d07cedc3. It is recommended to apply a patch to fix this issue. Multiple endpoints are affected.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Reference
https://github.com/thinkgem/jeesite5/commit/3d06b8d009d0267f0255acc87ea19d29d07cedc3 https://github.com/thinkgem/jeesite5/issues/28 https://github.com/thinkgem/jeesite5/issues/28#issuecomment-3045862239 https://github.com/thinkgem/jeesite5/issues/29 https://vuldb.com/?ctiid.316758 https://vuldb.com/?id.316758 https://vuldb.com/?submit.616103 https://vuldb.com/?submit.616104
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
4.3
Related CNNVD
CNNVD-202507-2375 (Published: 2025-07-17)
Share on: