CVE-2024-23052: 5kcrm Wukong CRM

Critical severity, CVSS 9.8. EPSS: 4.9% chance of exploitation in the next 30 days.

An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.

Affected products

  • 5kcrm Wukong CRM: version 9.0.1_20191202 only

Published 2024-02-29. Last modified 2026-07-14.