CVE-2025-8852 – WuKongOpenSource WukongCRM File Upload API Response Handler Information Exposure Vulnerability

The following table lists the changes that have been made to the
CVE-2025-8852 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 11, 2025

    Action Type Old Value New Value
    Added Description A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
    Added CVSS V2 (AV:N/AC:L/Au:S/C:P/I:N/A:N)
    Added CWE CWE-200
    Added CWE CWE-209
    Added Reference https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/issues/26
    Added Reference https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/issues/26#issue-3272864284
    Added Reference https://vuldb.com/?ctiid.319383
    Added Reference https://vuldb.com/?id.319383
    Added Reference https://vuldb.com/?submit.624693
Share the Post:

Related Posts