thinkgem JeeSite URI Scheme form ResourceLoader.getResource server-side request forgery

CVE Details

Basic Information

Title thinkgem JeeSite URI Scheme form ResourceLoader.getResource server-side request forgery
Type cve
Published 2025-05-26T13:00:08.937Z
Last Seen

Product Information

Vendor thinkgem
Product JeeSite
Version 5.11.0

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A critical vulnerability in thinkgem JeeSite allows remote attackers to perform server-side request forgery (SSRF) attacks via the ResourceLoader.getResource function. This can be exploited to access internal resources and potentially compromise the server.
AI Severity Medium
Vendor thinkgem
Product JeeSite
Affected Version 5.11.0, 5.11.1

Additional Information

CVE List
CWE List CWE-918
Bulletin Family
Source Data thinkgem JeeSite 5.11.0
thinkgem JeeSite 5.11.1

Source Information

Source Data thinkgem JeeSite 5.11.0
thinkgem JeeSite 5.11.1
Source Link

Description

A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getResource of the file /cms/fileTemplate/form of the component URI Scheme Handler. The manipulation of the argument Name leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS Score Summary

Base Score: 5.3 (MEDIUM)

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.