---
id: CVE-2025-8852
title: A vulnerability was identified in WuKongOpenSource WukongCRM 11.0
summary: >-
  A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This
  affects an unknown part of the file /adminFile/upload of the component API
  Response Handler. The manipulation leads to information exposure through error
  message. It…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
  - CWE-209
  - CWE-209
vendor: 5kcrm
product: wukong_crm
affected:
  - wukong_crm = 11.0
published: '2025-08-11'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8852'
references:
  - url: 'https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/issues/26'
    label: cna@vuldb.com
  - url: >-
      https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/issues/26#issue-3272864284
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.319383'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.319383'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.624693'
    label: cna@vuldb.com
  - url: 'https://github.com/WuKongOpenSource/WukongCRM-11.0-JAVA/issues/26'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00361
epssPercentile: 0.27118
ingestedAt: '2026-07-15T13:44:02.903Z'
---

## Overview

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

## Affected

- `wukong_crm = 11.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
