{"id":"CVE-2025-60828","title":"WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.","summary":"WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-502"],"vendor":"5kcrm","product":"wukong_crm","affected":["wukong_crm = 9.0"],"published":"2025-10-08","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-60828","references":[{"url":"https://gist.github.com/ChangeYourWay/424478421d6a78d1f87d324cddcbfd59","label":"cve@mitre.org"},{"url":"https://github.com/ChangeYourWay/post/blob/main/WukongCRM-9.0-JAVA.md","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.00361,"epssPercentile":0.29907,"ingestedAt":"2026-07-15T13:44:03.203Z","slug":"CVE-2025-60828","body":"## Overview\n\nWukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.\n\n## Affected\n\n- `wukong_crm = 9.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}