CVE-2025-7763
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-17

Last updated on: 2026-04-29

Assigner: VulDB

Description
A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the function select of the file src/main/java/com/jeesite/modules/cms/web/SiteController.java of the component Site Controller. The manipulation of the argument redirect leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 3d06b8d009d0267f0255acc87ea19d29d07cedc3. It is recommended to apply a patch to fix this issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-17
Last Modified
2026-04-29
Generated
2026-05-27
AI Q&A
2025-07-18
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
jeesite jeesite to 5.12.1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an open redirect issue found in the thinkgem JeeSite software up to version 5.12.0, specifically in an unknown function of the Site Controller/SSO component. An attacker can manipulate the system to redirect users to malicious sites. The vulnerability can be exploited remotely and affects multiple endpoints.


How can this vulnerability impact me? :

The vulnerability can be exploited to redirect users to malicious websites, potentially leading to phishing attacks or other malicious activities. This can harm users by exposing them to scams or malware and damage the reputation of the affected site.


What immediate steps should I take to mitigate this vulnerability?

Apply the patch identified as 3d06b8d009d0267f0255acc87ea19d29d07cedc3 to fix the vulnerability. It is recommended to update thinkgem JeeSite to a version later than 5.12.0 where this issue is resolved.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart