WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.
References
| Link | Resource |
|---|---|
| https://gist.github.com/ChangeYourWay/424478421d6a78d1f87d324cddcbfd59 | Third Party Advisory |
| https://github.com/ChangeYourWay/post/blob/main/WukongCRM-9.0-JAVA.md | Exploit |
Configurations
History
No history.
Information
Published : 2025-10-08 14:15
Updated : 2025-10-10 16:17
NVD link : CVE-2025-60828
Mitre link : CVE-2025-60828
CVE.ORG link : CVE-2025-60828
JSON object : View
Products Affected
5kcrm
- wukongcrm
CWE
CWE-502
Deserialization of Untrusted Data
