CVE-2025-8516

MEDIUM

Kingdee Cloud-Starry-Sky Enterprise Edition <8.2 - Path Traversal

Title source: llm
STIX 2.1

Description

A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file K3Cloud\BBCMallSite\WEB-INF\lib\Kingdee.K3.O2O.Base.WebApp.jar!\kingdee\k3\o2o\base\webapp\action\FileUploadAction.class of the component IIS-K3CloudMiniApp. The manipulation of the argument filePath leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. It is suggested to install a patch to address this issue. The vendor recommends as a short-term measure to "[t]emporarily disable external network access to the Kingdee Cloud Galaxy Retail System or set up an IP whitelist for access control." The long-term remediation will be: "Install the security patch provided by the Starry Sky system, with the specific solutions being: i) Adding authentication to the vulnerable CMKAppWebHandler.ashx interface; ii) Removing the file reading function."

References (6)

Core 6
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.318642
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.318642
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.573678
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.601912
Various Sources patch
https://vip.kingdee.com/link/s/ZgAmJ

Scores

CVSS v3 5.3
EPSS 0.0085
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (3)
Kingdee/Cloud-Starry-Sky Enterprise Edition 8.0
Kingdee/Cloud-Starry-Sky Enterprise Edition 8.1
Kingdee/Cloud-Starry-Sky Enterprise Edition 8.2
Published Aug 04, 2025
Tracked Since Feb 18, 2026