Remote Code Execution Vulnerability in Kingdee Cloud-Starry-Sky Enterprise Edition
CVE-2025-6761
6.9MEDIUM
What is CVE-2025-6761?
A remote code execution vulnerability exists in Kingdee Cloud-Starry-Sky Enterprise Edition versions 6.x through 9.0. The issue involves improper neutralization of special elements within the Freemarker Engine's plugin.buildMobilePopHtml function. This vulnerability can be exploited by attackers to manipulate template processing, potentially leading to unauthorized remote code execution. The vendor has released a patch to mitigate this risk by configuring the Freemarker resolver to 'ALLOWS_NOTHING_RESOLVER', preventing the parsing of any malicious classes. Immediate upgrading of the affected product is strongly recommended.
Affected Version(s)
Cloud-Starry-Sky Enterprise Edition 6.x
Cloud-Starry-Sky Enterprise Edition 7.x
Cloud-Starry-Sky Enterprise Edition 8.x