CVE-2025-7763 Information

Description

A vulnerability which was classified as problematic was found in thinkgem JeeSite up to 5.12.0. Affected is an unknown function of the component Site Controller/SSO. The manipulation leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 3d06b8d009d0267f0255acc87ea19d29d07cedc3. It is recommended to apply a patch to fix this issue. Multiple endpoints are affected.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Reference

https://github.com/thinkgem/jeesite5/commit/3d06b8d009d0267f0255acc87ea19d29d07cedc3 https://github.com/thinkgem/jeesite5/issues/28 https://github.com/thinkgem/jeesite5/issues/28#issuecomment-3045862239 https://github.com/thinkgem/jeesite5/issues/29 https://vuldb.com/?ctiid.316758 https://vuldb.com/?id.316758 https://vuldb.com/?submit.616103 https://vuldb.com/?submit.616104

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

4.3

CNNVD-202507-2375 (Published: 2025-07-17)

Share on: