Remote Code Execution Vulnerability in Kingdee Cloud-Starry-Sky Enterprise Edition
CVE-2025-6761

6.9MEDIUM

Key Information:

Vendor

Kingdee

Vendor
CVE Published:
27 June 2025

What is CVE-2025-6761?

A remote code execution vulnerability exists in Kingdee Cloud-Starry-Sky Enterprise Edition versions 6.x through 9.0. The issue involves improper neutralization of special elements within the Freemarker Engine's plugin.buildMobilePopHtml function. This vulnerability can be exploited by attackers to manipulate template processing, potentially leading to unauthorized remote code execution. The vendor has released a patch to mitigate this risk by configuring the Freemarker resolver to 'ALLOWS_NOTHING_RESOLVER', preventing the parsing of any malicious classes. Immediate upgrading of the affected product is strongly recommended.

Affected Version(s)

Cloud-Starry-Sky Enterprise Edition 6.x

Cloud-Starry-Sky Enterprise Edition 7.x

Cloud-Starry-Sky Enterprise Edition 8.x

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

caichaoxiong (VulDB User)
.