PT-2025-27075 · Kingdee+1 · Kingdee Cloud-Starry-Sky Enterprise Edition+1
Caichaoxiong
·
Published
2025-06-27
·
Updated
2025-07-02
·
CVE-2025-6761
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Kingdee Cloud-Starry-Sky Enterprise Edition versions 6.x through 9.0
Description:
A critical issue has been found, affecting the function
plugin.buildMobilePopHtml of the file k3o2oboswebappactionDynamicForm 4 Action.class of the component Freemarker Engine. This issue leads to improper neutralization of special elements used in a template engine, allowing for remote attacks. The exploit has been disclosed publicly.Recommendations:
For Kingdee Cloud-Starry-Sky Enterprise Edition versions 6.x through 9.0, it is recommended to upgrade the affected component, as the fixed release sets Freemarker to 'ALLOWS NOTHING RESOLVER' to prevent parsing any classes.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freemarker Engine
Kingdee Cloud-Starry-Sky Enterprise Edition