PT-2025-41259 · Wukongcrm · Wukongcrm

Changeyourway

·

Published

2025-10-08

·

Updated

2025-10-08

·

CVE-2025-60828

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions WukongCRM version 9.0-JAVA
Description The software contains a fastjson deserialization issue through the /OaExamine/setOaExamine API endpoint. The vulnerability is triggered via this interface.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-60828

Affected Products

Wukongcrm