Home

Description

EN DE

A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file modules/core/src/main/java/com/jeesite/common/ueditor/ActionEnter.java of the component UEditor Image Grabber. Such manipulation of the argument Source leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The name of the patch is 1c5e49b0818037452148e0f8ff69ed04cb8fefdc. It is advisable to implement a patch to correct this issue.

Es wurde eine Schwachstelle in thinkgem JeeSite up to 5.12.0 entdeckt. Dabei betrifft es einen unbekannter Codeteil der Datei modules/core/src/main/java/com/jeesite/common/ueditor/ActionEnter.java der Komponente UEditor Image Grabber. Die Bearbeitung des Arguments Source verursacht server-side request forgery. Der Angriff kann über das Netzwerk passieren. Die Ausnutzung wurde veröffentlicht und kann verwendet werden. Die Bezeichnung des Patches lautet 1c5e49b0818037452148e0f8ff69ed04cb8fefdc. Es ist ratsam, einen Patch zu implementieren, um dieses Problem zu beheben.

PUBLISHED Reserved 2025-07-17 | Published 2025-07-17 | Updated 2025-10-20 | Assigner VulDB




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
MEDIUM: 6.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
MEDIUM: 6.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
6.5AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C

Problem types

Server-Side Request Forgery

Product status

5.0
affected

5.1
affected

5.2
affected

5.3
affected

5.4
affected

5.5
affected

5.6
affected

5.7
affected

5.8
affected

5.9
affected

5.10
affected

5.11
affected

5.12.0
affected

Timeline

2025-07-17:Advisory disclosed
2025-07-17:VulDB entry created
2025-10-20:VulDB entry last update

Credits

MentalityXt finder

ZAST.AI (VulDB User) reporter

References

github.com/thinkgem/jeesite5/issues/27 exploit

vuldb.com/?id.316749 (VDB-316749 | thinkgem JeeSite UEditor Image Grabber ActionEnter.java server-side request forgery) vdb-entry technical-description

vuldb.com/?ctiid.316749 (VDB-316749 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.615769 (Submit #615769 | JeeSite https://github.com/thinkgem/jeesite5 JeeSite <=5.12.0 SSRF) third-party-advisory

github.com/MentalityXt/jeesite_ssrf/tree/main exploit

github.com/thinkgem/jeesite5/issues/27 issue-tracking

github.com/...ommit/1c5e49b0818037452148e0f8ff69ed04cb8fefdc patch

cve.org (CVE-2025-7759)

nvd.nist.gov (CVE-2025-7759)

Download JSON