VulnerabilityAnalyzed
CVE-2025-8852
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0.
LOW 2.1EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-209
- Affected
- 5kcrm/wukong crm
- Source
- cna@vuldb.com
References
- https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/issues/26Exploit, Issue Tracking, Vendor Advisory
- https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/issues/26#issue-3272864284Exploit, Issue Tracking
- https://vuldb.com/?ctiid.319383Permissions Required, VDB Entry
- https://vuldb.com/?id.319383Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.624693Third Party Advisory, VDB Entry
- https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/issues/26Exploit, Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.