{"id":"CVE-2025-7863","summary":"thinkgem JeeSite ServletUtils.java redirectUrl","details":"A vulnerability was found in thinkgem JeeSite up to 5.12.0 and classified as problematic. Affected by this issue is the function redirectUrl of the file src/main/java/com/jeesite/common/web/http/ServletUtils.java. The manipulation of the argument url leads to open redirect. The attack may be launched remotely. The name of the patch is 3d06b8d009d0267f0255acc87ea19d29d07cedc3. It is recommended to apply a patch to fix this issue.","modified":"2026-08-12T03:51:24.142643759Z","published":"2025-07-20T02:14:06.422Z","database_specific":{"cwe_ids":["CWE-601"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7863.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"5.10"},{"last_affected":"5.10"},{"introduced":"5.11"},{"last_affected":"5.11"},{"introduced":"5.12.0"},{"last_affected":"5.12.0"}]}],"cna_assigner":"VulDB"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7863.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-7863"},{"type":"ADVISORY","url":"https://vuldb.com/?id.316976"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.618188"},{"type":"REPORT","url":"https://github.com/thinkgem/jeesite5/issues/30"},{"type":"REPORT","url":"https://github.com/thinkgem/jeesite5/issues/30#issuecomment-3045861920"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.316976"},{"type":"FIX","url":"https://github.com/thinkgem/jeesite5/commit/3d06b8d009d0267f0255acc87ea19d29d07cedc3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/thinkgem/jeesite","events":[{"introduced":"0"},{"fixed":"eeb530562393fb481690a8ef0cb3bb15503f29f0"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"5.12.1"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:jeesite:jeesite:*:*:*:*:*:*:*:*"}},{"type":"GIT","repo":"https://github.com/thinkgem/jeesite5","events":[{"introduced":"53ceb352e0fef4195d97df5b397a9499b39bd123"},{"fixed":"3d06b8d009d0267f0255acc87ea19d29d07cedc3"}],"database_specific":{"extracted_events":[{"introduced":"5.0"},{"last_affected":"5.0"},{"introduced":"5.1"},{"last_affected":"5.1"},{"introduced":"5.2"},{"last_affected":"5.2"},{"introduced":"5.3"},{"last_affected":"5.3"},{"introduced":"5.4"},{"last_affected":"5.4"},{"introduced":"5.5"},{"last_affected":"5.5"},{"introduced":"5.6"},{"last_affected":"5.6"},{"introduced":"5.7"},{"last_affected":"5.7"},{"introduced":"5.8"},{"last_affected":"5.8"},{"introduced":"5.9"},{"last_affected":"5.9"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["5.0","5.1","5.2","5.3","5.4","5.5","5.6","5.7","5.8","5.9","v5.12.0.vue","v5.9.1","v5.9.0","v5.8.1","v5.8.0","v5.7.1","v5.7.0","v5.6.0","v5.5.2","v5.5.1","v5.5.0","v5.4.0","v5.3.2","v5.3.1","v5.3.0","v5.2.2","v5.2.1","v5.2.0","v5.1.0","v5.0.4","v5.0.3","v5.12.0.springboo3","v5.11.1.springboo3","v5.11.0.springboo3","v5.10.1.springboo3","v5.10.0.springboot3","v5.9.2.springboot3","v5.9.1.springboot3","v5.0.2","v5.0.1","v5.0.0.1","v5.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7863.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X"}]}