thinkgem JeeSite
cpe:2.3:a:jeesite:jeesite:*:*:*:*:*:*:*
- <= 5.12.0
A critical server-side request forgery (SSRF) vulnerability has been identified in thinkgem JeeSite versions through 5.12.0. The issue arises in the UEditor Image Grabber component, specifically within the ActionEnter.java file. The vulnerability is triggered by manipulating the 'source' parameter, allowing remote attackers to send requests to internal or external resources on behalf of the server.
Exploitation of this vulnerability allows for server-side request forgery, where an attacker can make the server send requests to other servers or services, potentially leading to unauthorized data access or interaction with internal services.
To reproduce this vulnerability, send a POST request to the '/js/a/file/ueditor/catchimage' endpoint with the 'fieldName' parameter set to 'source'. Include a 'source' parameter with a URL that can be controlled or monitored, such as a DNS log URL. The server will then make a request to the specified URL, demonstrating the SSRF vulnerability.
Users are advised to update to the latest version of thinkgem JeeSite, as the vulnerability has been patched. The patch is available in the commit identified by 1c5e49b0818037452148e0f8ff69ed04cb8fefdc.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.