Search Results (7 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108689 1 Wukongopensource 1 Wukong Aicrm 2026-10-11 5.4 Medium
Wukong AICRM through 20260610 contains a missing authorization vulnerability that allows authenticated users to write into other users' AI chat sessions by supplying an arbitrary sessionId to POST /chat/send. Attackers can append messages to a victim's conversation and receive streamed assistant replies built from the victim's last 20 messages, disclosing conversation content.
CVE-2026-108707 1 Wukongopensource 1 Wukong Hrm 2026-10-11 9.8 Critical
Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.
CVE-2026-108708 1 Wukongopensource 1 Wukong Hrm 2026-10-11 8.8 High
Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged employee can read payslips, salary records, bank cards and personal data, edit bank cards, and delete employees, departments and contracts company-wide.
CVE-2026-2141 2 5kcrm, Wukongopensource 2 Wukong Crm, Wukongcrm 2026-04-17 6.3 Medium
A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-60828 2 5kcrm, Wukongopensource 2 Wukong Crm, Wukongcrm 2025-10-10 6.5 Medium
WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.
CVE-2025-8852 2 5kcrm, Wukongopensource 2 Wukong Crm, Wukongcrm 2025-09-16 4.3 Medium
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-23052 2 5kcrm, Wukongopensource 2 Wukong Crm, Wukongcrm 2025-01-16 9.8 Critical
An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.