thinkgem
10 exploits
Active since Jul 2019
JeeSite 5.3 - Cross-Site Scripting via SkinName Parameter in Cookie Handler
Jeesite 1.2.7 - Authenticated SQL Injection via updateProcInsIdByBusinessId()
CVSS 6.5
Jeesite 1.2.7 - Authenticated XML External Entity Injection in ActProcessService
CVSS 6.5
JeeSite < 5.12.1 - Server-Side Request Forgery via UEditor Image Grabber Source Parameter
CVSS 6.3
thinkgem JeeSite <5.12.0 - Open Redirect
CVSS 4.3
thinkgem JeeSite <5.12.0 - Open Redirect
CVSS 4.3
thinkgem JeeSite <5.12.0 - Open Redirect
CVSS 3.5
thinkgem JeeSite <5.12.0 - Unrestricted Upload
CVSS 6.3
JeeSite < 5.12.0 - Cross-Site Scripting in XSS Filter
CVSS 3.5
JeeSite < 5.13.0 - Cross-Site Scripting via EncodeUtils.decodeUrl2
CVSS 3.5