{"id":"CVE-2025-7864","summary":"thinkgem JeeSite FileUploadController.java upload unrestricted upload","details":"A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been classified as critical. This affects the function Upload of the file src/main/java/com/jeesite/modules/file/web/FileUploadController.java. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 3585737d21fe490ff6948d913fcbd8d99c41fc08. It is recommended to apply a patch to fix this issue.","modified":"2026-08-12T15:15:03.033773Z","published":"2025-07-20T02:44:05.934Z","database_specific":{"cwe_ids":["CWE-284","CWE-434"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7864.json","unresolved_ranges":[{"extracted_events":[{"introduced":"5.10"},{"last_affected":"5.10"},{"introduced":"5.11"},{"last_affected":"5.11"},{"introduced":"5.12.0"},{"last_affected":"5.12.0"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulDB"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7864.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-7864"},{"type":"ADVISORY","url":"https://vuldb.com/?id.316977"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.618189"},{"type":"REPORT","url":"https://github.com/thinkgem/jeesite5/issues/31"},{"type":"REPORT","url":"https://github.com/thinkgem/jeesite5/issues/31#issuecomment-3051363397"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.316977"},{"type":"FIX","url":"https://github.com/thinkgem/jeesite5/commit/3585737d21fe490ff6948d913fcbd8d99c41fc08"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/thinkgem/jeesite","events":[{"introduced":"0"},{"fixed":"eeb530562393fb481690a8ef0cb3bb15503f29f0"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"5.12.1"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:jeesite:jeesite:*:*:*:*:*:*:*:*"}},{"type":"GIT","repo":"https://github.com/thinkgem/jeesite5","events":[{"introduced":"53ceb352e0fef4195d97df5b397a9499b39bd123"},{"fixed":"3585737d21fe490ff6948d913fcbd8d99c41fc08"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"5.0"},{"last_affected":"5.0"},{"introduced":"5.1"},{"last_affected":"5.1"},{"introduced":"5.2"},{"last_affected":"5.2"},{"introduced":"5.3"},{"last_affected":"5.3"},{"introduced":"5.4"},{"last_affected":"5.4"},{"introduced":"5.5"},{"last_affected":"5.5"},{"introduced":"5.6"},{"last_affected":"5.6"},{"introduced":"5.7"},{"last_affected":"5.7"},{"introduced":"5.8"},{"last_affected":"5.8"},{"introduced":"5.9"},{"last_affected":"5.9"}]}}],"versions":["5.0","5.1","5.2","5.3","5.4","5.5","5.6","5.7","5.8","5.9","v5.12.0.vue","v5.9.1","v5.9.0","v5.8.1","v5.8.0","v5.7.1","v5.7.0","v5.6.0","v5.5.2","v5.5.1","v5.5.0","v5.4.0","v5.3.2","v5.3.1","v5.3.0","v5.2.2","v5.2.1","v5.2.0","v5.1.0","v5.0.4","v5.0.3","v5.12.0.springboo3","v5.11.1.springboo3","v5.11.0.springboo3","v5.10.1.springboo3","v5.10.0.springboot3","v5.9.2.springboot3","v5.9.1.springboot3","v5.0.2","v5.0.1","v5.0.0.1","v5.0.0"],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/thinkgem/jeesite5/commit/3585737d21fe490ff6948d913fcbd8d99c41fc08","target":{"file":"common/src/test/java/com/jeesite/test/codec/EncodeUtilsTest.java"},"deprecated":false,"digest":{"line_hashes":["241989943472768683314586128908225273903","149489220394225014978855575702157730239","179622916099826689265776724692605855962","288900956835368455450134093614049238159","299546520859880494344318158684224530509","51347088489505154742826988304578999648","290517988987259402545228750687015323312","288703041537910496659359321103654158909","23967616208374119495887708471187206749","286279972174570209427080225523563136955","217943920223534221271068183730496100115","248871320011893251274022376493073993790","330983712602585453968107632566496324389","222802299120601114139020302214614908826","210560381570499459337072600259830553567","266791444599844889562839805311719729980","94023364322555776142773219748367861473","156195478251057118249440027891807764701","327469038203108564414684751481639054763","251635235219299523100999556267549079182","157668419006944688626038965730425105668","261167840647540292835149960906423500210","18328013884261927084124147847666818224","38976876792977973308906727155702151946","302169975737532133947064485423270842393","235075867460382682757924068583259039615","277174943573020508531374644763658854512","81721049033289732796040626323615544265","292207743392704153029929677243968641746","181460993830192581180487545699566777896","26596726663821680829155700164406748989","58249707093083774687237989500646489832","33240807574261382001935940431014988921"],"threshold":0.9},"id":"CVE-2025-7864-19e035d9","signature_type":"Line"},{"target":{"file":"common/src/main/java/com/jeesite/common/codec/EncodeUtils.java"},"deprecated":false,"digest":{"line_hashes":["177485928619821022511948781053094846858","185975085118491526123660578194007812501","277945111815014043841698570543593225903","267772397607222657853423109493088497017"],"threshold":0.9},"id":"CVE-2025-7864-29ee259c","signature_type":"Line","signature_version":"v1","source":"https://github.com/thinkgem/jeesite5/commit/3585737d21fe490ff6948d913fcbd8d99c41fc08"},{"source":"https://github.com/thinkgem/jeesite5/commit/3585737d21fe490ff6948d913fcbd8d99c41fc08","target":{"file":"common/src/test/java/com/jeesite/test/codec/EncodeUtilsTest.java","function":"main"},"deprecated":false,"digest":{"function_hash":"327511496877213566562467200940784426822","length":2905},"id":"CVE-2025-7864-651434ad","signature_type":"Function","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7864.json","vanir_signatures_modified":"2026-08-12T15:15:03Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}