CVE-2025-8852

low

Description

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

References

https://vuldb.com/?submit.624693

https://vuldb.com/?id.319383

https://vuldb.com/?ctiid.319383

https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/issues/26#issue-3272864284

https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/issues/26

Details

Source: Mitre, NVD

Published: 2025-08-11

Updated: 2025-08-11

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Medium

CVSS v4

Base Score: 2.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Severity: Low

EPSS

EPSS: 0.00029