CVE-2025-8852

MEDIUM

WukongCRM 11.0 - Information Exposure via API Response Handler Error Message

Title source: llm
STIX 2.1

Description

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
https://vuldb.com/?id.319383
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.319383
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.624693
Exploit, Issue Tracking, Vendor Advisory issue-tracking
https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/issues/26

Scores

CVSS v3 4.3
EPSS 0.0032
EPSS Percentile 23.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-209
Status published
Products (1)
5kcrm/wukongcrm 11.0
Published Aug 11, 2025
Tracked Since Feb 18, 2026