WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.
https://github.com/ChangeYourWay/post/blob/main/WukongCRM-9.0-JAVA.md
https://gist.github.com/ChangeYourWay/424478421d6a78d1f87d324cddcbfd59