{"id":"CVE-2024-23052","title":"An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.","summary":"An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-502","CWE-502"],"vendor":"5kcrm","product":"wukong_crm","affected":["wukong_crm = 9.0.1_20191202"],"published":"2024-02-29","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-23052","references":[{"url":"https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/WukongCRM_9.0.md#1remote-code-execution-vulnerability","label":"cve@mitre.org"},{"url":"https://github.com/WuKongOpenSource/WukongCRM-9.0-JAVA/issues/28","label":"cve@mitre.org"},{"url":"https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/WukongCRM_9.0.md#1remote-code-execution-vulnerability","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/WuKongOpenSource/WukongCRM-9.0-JAVA/issues/28","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.04912,"epssPercentile":0.91734,"ingestedAt":"2026-07-14T15:37:09.823Z","slug":"CVE-2024-23052","body":"## Overview\n\nAn issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.\n\n## Affected\n\n- `wukong_crm = 9.0.1_20191202`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":53.9,"likelihood":1,"exploitation":0,"ransomware":0},"changes":[]}