Vulnerabilities > CVE-2024-23052 - Deserialization of Untrusted Data vulnerability in 5Kcrm Wukongcrm 9.0.120191202
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
References
- https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/WukongCRM_9.0.md#1remote-code-execution-vulnerability
- https://github.com/By-Yexing/Vulnerability_JAVA/blob/main/2024/WukongCRM_9.0.md#1remote-code-execution-vulnerability
- https://github.com/WuKongOpenSource/WukongCRM-9.0-JAVA/issues/28
- https://github.com/WuKongOpenSource/WukongCRM-9.0-JAVA/issues/28