Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-9796

Опубликовано: 01 сент. 2025
Источник: nvd
CVSS3: 3.5
CVSS3: 4.1
CVSS2: 4
EPSS Низкий

Описание

A vulnerability was found in thinkgem JeeSite up to 5.12.1. This affects the function decodeUrl2 of the file common/src/main/java/com/jeesite/common/codec/EncodeUtils.java. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version 5.13.0 mitigates this issue. The patch is identified as 63773c97a56bdb3649510e83b66c16db4754965b. Upgrading the affected component is recommended.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jeesite:jeesite:*:*:*:*:-:*:*:*
Версия до 5.13.0 (исключая)

EPSS

Процентиль: 11%
0.00039
Низкий

3.5 Low

CVSS3

4.1 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 3.5
github
около 1 месяца назад

A vulnerability was found in thinkgem JeeSite up to 5.12.1. This affects the function decodeUrl2 of the file common/src/main/java/com/jeesite/common/codec/EncodeUtils.java. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version 5.13.0 mitigates this issue. The patch is identified as 63773c97a56bdb3649510e83b66c16db4754965b. Upgrading the affected component is recommended.

EPSS

Процентиль: 11%
0.00039
Низкий

3.5 Low

CVSS3

4.1 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-79
CWE-79