Remote Code Execution Vulnerability in Kingdee Cloud-Starry-Sky Enterprise Edition
CVE-2025-6761
What is CVE-2025-6761?
A remote code execution vulnerability exists in Kingdee Cloud-Starry-Sky Enterprise Edition versions 6.x through 9.0. The issue involves improper neutralization of special elements within the Freemarker Engine's plugin.buildMobilePopHtml function. This vulnerability can be exploited by attackers to manipulate template processing, potentially leading to unauthorized remote code execution. The vendor has released a patch to mitigate this risk by configuring the Freemarker resolver to 'ALLOWS_NOTHING_RESOLVER', preventing the parsing of any malicious classes. Immediate upgrading of the affected product is strongly recommended.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cloud-Starry-Sky Enterprise Edition 6.x
Cloud-Starry-Sky Enterprise Edition 7.x
Cloud-Starry-Sky Enterprise Edition 8.x
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
