CVE-2025-7759 | thinkgem JeeSite up to 5.12.0 UEditor Image Grabber ActionEnter.java Source server-side request forgery (EUVD-2025-21831)
A vulnerability described as critical has been identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file modules/core/src/main/java/com/jeesite/common/ueditor/ActionEnter.java of the component UEditor Image Grabber. Such manipulation of the argument Source leads to server-side request forgery.
This vulnerability is listed as CVE-2025-7759. The attack may be performed from remote. In addition, an exploit is available.
It is advisable to implement a patch to correct this issue.