Executive brief
WukongCRM, a popular open-source Customer Relationship Management (CRM) platform, contains a security flaw in its office automation examination module. An attacker can exploit this vulnerability to disrupt the service or potentially gain unauthorized control over the server. This could lead to business operations being halted or the exposure of sensitive customer and sales data.
Technical details
A deserialization vulnerability (CWE-502) exists in WukongCRM-9.0-JAVA within the OaExamineController class. The application uses an unsafe version of the fastjson library to process request bodies sent to the /OaExamine/setOaExamine endpoint. By sending a specially crafted JSON payload, a remote, unauthenticated attacker can trigger a denial of service (DoS). If 'autoTypeSupport' is enabled and specific dependencies are present, the vulnerability can be escalated to Remote Code Execution (RCE) via JNDI injection (e.g., using LDAP). The issue is similar to CVE-2024-23052.
Affected products
- 5kcrm WukongCRM-9.0-JAVA 72crm_9.0.1_20191202
Timeline
- 2025-10-08: disclosed: Vulnerability details and PoC published by researcher ChangeYourWay.
- 2025-10-08: advisory: CVE-2025-60828 assigned and published.