CVE-2025-8852

MEDIUM

5kcrm Wukongcrm - Information Disclosure

Title source: rule
STIX 2.1

Description

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 4.3
EPSS 0.0006
EPSS Percentile 18.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-209
Status published
Products (1)
5kcrm/wukongcrm 11.0
Published Aug 11, 2025
Tracked Since Feb 18, 2026